Thanks for your help on this.Perhaps I'm misunderstanding or didn't explain the situation correctly. Are you saying that the meanings of "in" and "out" are reversed in OPNsense, from what I'm used to in other contexts?
For example, if my LAN client computer makes a web request, I think of this as being an "in" at the LAN interface, and an "out" at the WAN/outside interface.
To be clear -- I do have an "allow in and out" rule for the LAN interface (again... it seems it needed to be in the floating rules), but the one that I'm concerned about is on the WAN interface where I need to "allow in", which is like opening the door wide open, when I only want statefully established responses allowed in.