pf(4) as a NAT44 router
pf
(4) is a bit optimistic with regard to how many states it can track using the defaults.
[zone: pf states] PF states limit reached
Raising the hard limits to four times the default seems better:
set limit { states 40000, src-nodes 40000, frags 20000, table-entries 800000 }