Hi Tammy,
For a short period of time (during the 3-way TCP handshake) these flows are counted as a TCP connection and therefore counted in the license.If the TCP session are determined to be placed in "pass-through"this one session is deducted from the count.
The "current" usage can be determined by issuing "show stat tfo".
Sometime when a client is infected and tries to set up a lot of sessions (or port-scan like application) you can encounter overload situations on a WAAs devices, because the client spawns a lot of TCP sessions, which never gets established.
Best regards
Finn