This has nothing to do with the direction of the packets you want to filter accordingly. Normally, enforcing policies is on (1.) [receiving interface] and rarely on (2.) [sending interface], because why would you forward something through a firewall if you are going to discard it when it is ready to exit?