When you say you can 'see' these things, are you looking in the audit or in tcpdumps?
The firewall does not audit every single packet, so if you see a packet in the audit but don't see a reply packet in the audit that's not a concern, necessarily
If you are looking at tcpdumps on the firewall and you see a packet come in, traverse the firewall, leave the firewall, but no reply comes back, then you have an issue somewhere else on your network. If you see packets go through the firewall and a reply comes back to one side of the firewall but doesn't go back out the other side, then the firewall could be at fault (or it's routing the packet somewhere else, i.e. not out the interface you're doing a tcpdump on).
I would take tcpdumps on the incoming and outgoing interfaces of the firewall. Does each packet that comes in leave the other side of the firewall? Do responses come back?
Doh! I was looking in the audit reports ... will try tcpdump tomorrow. Thanks for the reminder! (Been several weeks since I last worked in the firewall and , I swear, you gotta practically retriain me after that long!)
Don't forget that you can take packet captures in the UI (Admin Console and ControlCenter).