JW88,
your statement "All traffic is allowed thru your firewall until you either load the initial policy (which blocks all inbound traffic) or you reload your existing policy" is NOT correct.
when you do "fw unloadlocal" forwarding is OFF as well.
If you want to turn the device a router, you have to do
this:
Nokia: ipsofwd admin on
SPLAT: echo 1 > /proc/sys/net/ipv4/ip_forward
without it, traffics can not come in from one interface and
out the other.