2009-07-02 23:55:02 UTC
Are you sure you are not having routing problems? A common error is to have a different path for the packets coming in, and another for the packets going out. If this is the case, it is common to have packet drops.
Normally, the packets logged by firehol contain the reason if you take a closer look. What interface name do the packets log? Which src/dst? Do they match firehol.conf?