Hi for the 5GT, there is a specific KB which explains the issue (KB 4566):
http://kb.juniper.net/index?page=content&id=KB4566&actp=search&searchid=1239229372523
Copy and pasting it for easy ref:
Synopsis:
Why Are the 'Out Defer' Counters Incrementing When Traffic Flow Is Low?
The fact that the out defer counters are incrementing when traffic flow is low does not necessarily indicate a problem. If there is a large volume of data being sent out, sometimes there will be contention in the gateway with packets trying to exit the Untrust interface. The NS-5GT buffers the packets and defers transmission for later.
If the Trusted LAN has several hosts sending packets through the NS-5GT gateway, sometimes data needs to be buffered so that the NS-5GT can process the packets. Packets are examined for policy checking, AV, DI, URL filtering, logging, and anything else that is configured to be inspected.
This issue should not impact the traffic throughput or the performance of NS-5GT.
++++++++++++
Basically the out defer would mean that the FW is buffering the packets, it does not mean that the firewall is dropping packets.
For ease of mind, you can also do a snoop to check that each incoming packet is being sent out/ of course sniffer captures on ingress and egress are the best to compare though.