For anyone running into something similar in the future, the fix was to check "Disable reply-to on WAN rules" in the firewall advanced settings. I didn't really consider this before, as the only interface on this box is configured as a LAN interface.