Thanks for the information.
Yes it is a Cisco - I do not have access to our firewall and the network engineer is not here to query this with
I am just looking at "All Firewall Events" in LEM - checking event info...any idea what the "event info" is for a shun? I can see "ACL Inside Access in Denied TCP Packet" - this could be it?
Thanks