I set logging on the rules to emergency just so I can find them easy, the trace is below
Please ignore https names, it is actually http that I am forwarding and connecting to at the moment.
2009-10-21
12:53:51 Emergency CONN
600002 https_inbound_allow TCP wan1
vlan2 192.168.100.107
192.168.100.99 51644
80 conn_close
close
conn=close origsent=2712 termsent=748
2009-10-21
12:53:48 Emergency CONN
600002 https_inbound_allow TCP wan1
vlan2 192.168.100.107
192.168.100.99 51637
80 conn_close
close
conn=close origsent=3832 termsent=1712
2009-10-21
12:53:12 Emergency CONN
600001 https_inbound_allow TCP wan1
vlan2 192.168.100.107
192.168.100.99 51646
80 conn_open
satdestrule=https_inbound_map conn=open
2009-10-21
12:52:30 Emergency CONN
600004 nat_out UDP vlan2
core 192.168.2.2
224.0.0.251 5353
5353 conn_open_natsat
conn=open connnewsrcip=127.0.0.1 connnewsrcport=15305 connnewdestip=224.0.0.251 connnewdestport=5353
2009-10-21
12:52:30 Emergency CONN
600004 nat_out UDP vlan2
core 192.168.2.100
224.0.0.251 5353
5353 conn_open_natsat
conn=open connnewsrcip=127.0.0.1 connnewsrcport=10438 connnewdestip=224.0.0.251 connnewdestport=5353
2009-10-21
12:52:27 Emergency CONN
600001 https_inbound_allow TCP wan1
vlan2 192.168.100.107
192.168.100.99 51644
80 conn_open