Where were they dropped in the rulebase. if it is at rule 0, then it is because of the antispoofing configuration. If you can, please give a bit more information about your setup, and I will try to help you.

Also, I don't know if this is an option, but you might not want to config antispoofing on your firewall, but instead do it on your internet router via access-lists. Just a bit easier in my opinion.