The only way to prevent state tracking from killing partial connections is to disable state tracking in the pass rule, but you may want to lock that rule with an IP or something... "pass" all by itself is not enough.