Please draw a diagram of your network. The most common cause of unexpected "state violation" hits is asymmetric routing.Also in most cases you never need an "out" rule.