are my rules correct for such case?
nothing special seem to log, only regular TCPSequenceNumbers
2011-03-24 21:02:17 Debug TCP_FLAG 3300016 TCPSequenceNumbers TCP wan wan 80 58614 tcp_seqno_too_low drop
win2008r2 srv regular VPN client is used with certificate for ipsec and just PAP
know nothing about other side cisco
log shows on conn, nothing else
2011-03-24 21:08:05 Info CONN 600004 allow_l2tp UDP lan wan 195.X 500 500 conn_open_natsat
conn=open connnewsrcip=82.x connnewsrcport=22511 connnewdestip=195.x connnewdestport=500