Hey PB, I have recently noticed these types of log entries as well and was also curious why I don't understand. I *thought* I understood that a packet arriving at the gateway for an established connection already in the state table was not logged. But if the packet is a SYN request for a new connection it would be logged? And if there were already an entry in the state table for this connection that would indicate improver tear down on the prior connection? Is something strange going on here like a packet without a proper sequence number? But wouldn't that be dropped? A SYN packet that somehow randomly matches the sequence number of another connection in the state table?
I attached what I think you were asking for RE "Log Card" on an example.
Also I have to admit I'm not sure I have any experience with "logging individual connections versus consolidating into sessions", can you provide me a SK number or something?
Thanks for all of your good work --