When sniffing packets, fast-track is disabled. And if there isn’t a firewall rule allowing packets that would otherwise be fast-tracked, connections get dropped. Selection criteria in the “action=accept” rule don’t necessarily have to be identical to those in fast-track rule, but if they aren’t they should be less restrictive, i.e. they should pass all traffic fast-tracked.