Ive run into on at least two occasions where a customer has reched my tcp connection limit and the connections to them never drop. they stay active in the the firewall connections area.
right now i have the action set to reject-tcp reset. is that incorrect? should i be using drop instead? the default timeout values place a drop @ 60 seconds the tcp-reset should be instintainous shouldnt it?