At a guess, I'd say that it comes from the way your firewall uses syslog. Remember that the lish console is basically the equivalent of your normal virtual consoles on a real computer, and sometimes logging information is routed there if there's no specific configuration for it, I believe.
This being the case, you should be able to edit /etc/syslog.conf and look for a line for your firewall. I'm not entirely sure how syslog.conf is processed myself, but
http://www.shorewall.net/FAQ.htm#faq6 looks like it could help, assuming you use shorewall.