pf(4) as a NAT44 router
pf(4) is a bit optimistic with regard to how many states it can track using the defaults.
[zone: pf states] PF states limit reached
Raising the hard limits to four times the default seems better:
set limit {
states 40000,
src-nodes 40000,
frags 20000,
table-entries 800000
}