I have syslog configured to send to a host on my internal network, at a private IP address. That's working fine.
But when I capture packets with tcpdump on my external (WAN) interface, I see syslog packets addressed to that system there too. Is this intentional?