Ok,
So what would be like the best practice:
First Pre-filters - Like you mention on the video training. Then
ACP:
1- Allow inbound traffic to static NAT (inside Servers)
2- Monitor - all Traffic (for discovery)
3- Allow outgoing traffic from users (Url, application, malware and IPS)
4- Deny Any Any
Does the stateful feature still apply?
If I allow a packet to go out, would the return traffic make it in?)