The attacks are definatly coming from the outside. According to the event log ip addresses and who they are registered to.

I can run those programs and enumerate users fine from the inside.. however once inside the network, nothing really touches the firewall unless it goes back out again and tries to come in. However when I try from outside is when I cannot enumerate users, but i can enumerate groups.