Btw, FWIW, here is something that some folks may not realize, so definitely worth mentioning...so when you use ORDERED layers, like I did in my lab, traffic has to be ACCEPTED on every layer, otherwise, nothing will work, say if I had any any drop on last ordered layer. Same goes for inline layers...if traffic hits it, meaning hits "parent" rule, it will check "child" rules, if it matches one, goes on, if not, drops it, no more matching.
Truth be told, thats how it really works with any other fw vendor. Top to bottom, left to right order.
Best,
Andy