Thanks for the responses. I have the IPS blade on a limited scope at the moment as I am testing so I will try disabling this to see if this makes a difference.
The rule is actually one of the mgmt rules where a few host groups have access to the FW cluster and gateway addresses.
It has nothing to do with with outbound access at all which is why I am confused at to why its even:-
a: this rule is getting involved at all
b: its an accept rules anyway so should not be dropping
There is nothing in the logs BTW - I only see the drops when using fw ctl zdebug
Jon