I saw that in the manual one time and have always wondered that myself. How can it say it just allows everything implying that somehow traffic can just magically get inside the network without the problems of port forwarding. That would be so nice sometimes when port forwarding is being a pain.
I am suspecting what it does if you set it to say normal it provides some extra layer of protection for devices that you do have port forwarded or in the DMZ.
With a commercial firewall we run have these type of protection on all the time to prevent things like half open session attacks against a server but these are non natted addresses. When you are running NAT sure a outside machine can try to half open a bunch of session with your...