@planedrop Yep, recognize you from the Unifi forums. Running pfSense in front of my UDMP has worked out great once I sorted out the Outbound NAT rules. For the last 30 days, I haven't had a need to touch anything in pfSsense, it just works.
So other than load balancing my 2 WANs, I don't do anything on pfSense, everything else is happening on the UDMP. I don't have any port forwarding in place right now as I don't really need it, but my VPN to my work machine on a corporate network (using Cisco Anyconnect) has been working flawlessly from my personal home workstation.
That said, I would imagine that in order to make port forwarding work properly, one would have to make entries on both the UDMP as well as in pfSense and I'd imagine pfSense will let you make port forwards sticky on one WAN or the other.
As I mentioned on the UniFi forum, once I get my dual symmetrical GigE WANs up and running, and be doing some benchmarks from machines behind the UDMP, as well as from a box hanging directly off the pfSense appliance.