wish to do some debug but i don't know how
noticed that some connections are blocked by the firewall at packet 0, hard to believe there was a packet -1.
sharing actual rule parameters (with some sanitizing if needed) and dropped packet info (catch dropped packet in live view and hit "i" button in packet string) would be helpful imho.
and it should be blocked at first packet. probably the out-of-statehttps://forum.opnsense.org/index.php?topic=20219.0