estab is the keyword for packets not tagged w/ the 'syn' bit, right? so evaluate estab would be to allow traffic permitted out to come back in? estab packets do not have a send or receive direction, so there is no way to differentiate which TCP packets are incoming or outgoing.
sorry if the above doesn't make sense. i'm just confused about what this one line does, and it's not clear to me yet.
thanks for all your help.