Aaaaand… I broke it again - same behavior. Unclear exactly how I did that. I was putting some Snort stuff together, but even suspecting that, and disabling it, still get no-resume behavior (testing from one of the WAN interface sides.
Interestingly, if I reverse the scenario - start downloading a file from the LAN side, pull a cable, that does resume. So it is somehow related to the WAN side, or the number of VIPS/1:1NATs I have? B/c WAN, DMZ, and LAN are all using CARP VIPs. I'll do some more testing, but yes, FW2 (looking in Diag->States) does have that in there (http connection), so states are synching.