You can use TTL to determine if the packets are making it downstream of the firewall.

http://www.packetfactory.net/projects/firewalk/

-Maestr0