I'm trying to understand why some outbound :80 and :443 connections are being blocked by "Default deny rule". Can anyone offer advice on debugging this?
e.g.
LAN -> 10.1.1.129:58809 34.225.72.208:443 tcp Default deny rule
These connections seem legitimate to me.
its normal. most likely because of flags\states. for example if connection is reset by peer and host from lan keep send some traffic
search for "out-of-state traffic"... comes up here 2-3 times a month