I really haven't started looking into the code .... but
should the checkstate rule show packet accounting matches.....
09000 0 0 check-state
09500 16194 1609751 allow tcp from x.x.x.x to any keep-state out xmit
fxp0 setup
yet there are packet matches in the dynamic rules .....
--
Email: skafte@worldgate.ca Voice: +780 413 1910 Fax: +780 421 4929
#575 Sun Life Place * 10123 99 Street * Edmonton, AB * Canada * T5J 3H1
-- --
When things can't get any worse, they simplify themselves by getting a
whole lot worse then complicated. A complete and utter disaster is the
simplest thing in the world; it's preventing one that's complex.
(Janet Morris)