You can enable logging on the firewall rule that passes traffic for that. If it's passed by a catch-all rule you can add a more specific pass rule above that to catch only that. Steve