Apache can sometimes cause problems when configured certain ways in certain environments with certain clients.
If you setup Apache behind a pfSense firewall you might notice a lot of FINWAIT2 states in your table. This isn't necessary, and as I understand it is caused by sloppy http clients that never send the FIN/ACK to close the tcp connection.
There are a few things I've done to alleviate this issue:
The more I read about this, the more I feel its not a serious problem, unless you have several thousand FINWAIT2 states. The one's I'm mostly confused about are the ones from the firewall to the server:
192.168.3.1:43147 -> 192.168.3.2:80
There are usually many of these, and I'm not sure exactly why there needs to be so many. I think it may be since I'm using the load balancer, instead of simple nat, which I think would directly use the web server's settings for keeping state.
Thankfully, pfSense has the "advanced" option for each firewall rule. I went into the rule for port 80, and reduced the timeout for that rule to 20, though I may reduce it more.