;FW-1: fw_log_bad_conn_ex: reason ICMP error does not match an existing connection;
;fw_log_drop_ex: Packet proto=1 ... dropped by fw_first_packet_state_checks Reason: ICMP error does not match an existing connection;
;fw_handle_first_packet: first packet state violation (action=VANISH);
;fw_filter_chain: handle_first_packet returned action VANISH for new conn;
ICMP Error packet arrives through the firewall while the original connection (For which the ICMP error was generated) did not go through the firewall. (For example, asymmetric routing).