Will a PIX running 6.3.5 drop incoming packets that have an incorrect TCP checksum? If so, can that option be modified in any way? The PIX in question has a basic config, nothing out of the ordinary. Several static NAT's, some basic ACL's, all of the default fixups and sysopts.