These are the possibilities i could think of :-
1) Your main IP is on eth1 and you have APF configured for eth0.
2) You have multiple uncommented entries of IG_TCP_CPORTS in apf conf. Only the last entry matters.
Before that, check whether its APF only that controls your firewall. To check that - stop your apf and list your iptables rules ( iptables -L -n ). If you still have non-empty rulesets listed, apf no longer has any control over the firewall. In that case, you will need to dig further