From network services, I'm only running DNSCypt proxy and ntp, no web proxy. Yet, I see way too much traffic falling under "let out anything from firewall host itself" rule (src is the WAN IP dest is internet). Any suggestions on how to log or some other way to find out which processes are sending traffic to the internet?
Btw, I already turned off "let out anything from firewall host itself (force gw)" rule.