If I create a rule: pass out quick on $iface proto tcp from any to any flags S/SA modulate state the connections don't initiate. Replacing 'flags S/SA modulate state' to 'keep state' salvages this.