I think this kernel variable may allow you to monitor packets that are out of state (even if they aren't dropped), but it does not appear to be documented. Use at your own risk or perhaps ask TAC, default value is 0:
fw_tcp_out_of_state_monitor = 0
Edit: My guess (confirm this with TAC) is that if this variable is set to 1 and both "drop out of state TCP" and "log on drop" is checked, out of state TCP packets will be logged but not actually dropped as the enforcement is placed in "monitor" mode.
This could be an interesting technique for sites that have had "drop out of state TCP" unchecked for a long time, and are afraid to recheck it because of what it might break. If my guess is correct the "drop out of state TCP" and "log on drop" boxes could be checked in that situation, and this variable set to 1. This would allow kind of a "preview" of what would happen in the logs if the checkbox was to be rechecked, but without actually breaking anything.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com