Use 'snoop' for packets outside the firewall, and 'debug' for inside.
For instance, 'debug flow drop' will catch all dropped packets (view by 'get db st', clear by 'clear db', turn off by 'undebug all').
You can also set a filter and do 'debug flow basic', actually there's a TON of debugs you can use. Set a filter like:
set ffilter src-ip x.x.x.x dst-ip x.x.x.x
there are a bunch of options, you really need to mess with it to get the hang of it.
Try typing 'snoop ?'
"I would rather have a free bottle in front of me, than a pre-frontal lobotomy..."
-Shrubble