pfSense+ firewall

I have a packet capturing and a Syslog collector. The firewall log contains, chronologically, a pass entry and after that some blocked entrys, for the same connection (source IP, destination IP, ports, etc).