# Packetbeat data is reverse

**URL:** <https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [April 15, 2021, 3:16am UTC](https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171 "2021-04-15T03:16:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ARDiver86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ardiver86/32/85266_2.png) [@ARDiver86](https://discuss.elastic.co/u/ARDiver86)\
**Post date:** [April 15, 2021, 3:16am UTC](https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171/1 "2021-04-15T03:16:22Z")

</div>

I'm noticing that a lot of data coming in from Packetbeat (if not all) is in reverse as far as traffic direction. For example we have a web server nat through a Fortigate firewall for port 443. Packetbeat is reporting the source ip and port is the internal server IP and port 443 and the destination is a public IP and a random port number. This actually should be reverse as it is the public IP communicating to our server on port 443.

Our current config is pretty much default except for the elasticsearch output and the packetbeat.interfaces.device parameter which is set to the correct nic when running ".\packetbeat.exe devices"

How can I correct this issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2021, 5:16am UTC](https://discuss.elastic.co/t/packetbeat-data-is-reverse/270171/2 "2021-05-13T05:16:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
