Please consider adding either a limit or alarm for session counts. This feature is highly valuable for finding virus infected nodes on a network and preventing DOS from the inside from killing the firewall. P4-3ghz machines frequently open 6000 sessions, four to five will kill many firewalls. Some brands like NetScreen have a limit by source, destination for each interface.
So you get an alarm and protect from DOS. Go to three nodes, unplug and remediate - network stays up. This is a GREAT support feature for Network admins.
Just a thought....