Let me summarize:
The vast majority of functionality is just fine. Thus layer 1 appears healthy.
From a statically addressed PC: Sometimes SOME Internet sites are unreachable, as described below, but most work just fine. Thus DNS, DHCP, cabling, DNAT rules, etc. are unlikely a problem.
From a statically addressed linux box: I've noticed intermittent access to zec.slushpool.com port 4444. I have 100% access from St. Louis, and "sometimes" access, lasting minutes to days, from a linux box behind the PFSense firewall of concern. A PC on a different port of that same concerning PFSense firewall also has "sometimes" access to zec.slushpool.com port 4444 - and access outages do not correlate between the PC and the linux box. I don't think there is anything special about zec.slushpool.com - it just happens to be the site the linux box and PC are configured to use.
From my 160+ DHCP addressed processing machines, all linux based, I've seen a couple of instances of not being able to reach their primary site oh1.kano.is and have confirmed with the operator of that site they were not experiencing any issues. Their backup site, stratum.kano.is functions fine when needed, so I only loose about 5 minutes of failover time. I'm stating this just because its likely related.
DNS resolution works fine ALL the time. Pinging of zec.slushpool.com fails when access stops.
Access to both zec.slushpool.com and oh1.kano.is will randomly and independently toggle, without any administrative changes occurring on the PFSense box. (Note that oh1.kano.is is AWS based and requires a TCP ping, not ICMP). Normally access is stable for hours - but under a curve. e.g. I've seen access for as little as a few minutes to days.
I have not specifically checked if the linux box can ping the firewall, but SSH sessions continue to work. Clearly the PC can access the firewall since most web browsing functions.
Rebooting the PFSense box will sometimes resolve the access issues although its become a guessing game as to any individual website working or not. Most do.
Changing my external static address resolved about 90% of the access issues, at least for now, but that only occurred a few days ago.
ALL of these problems started when I upgraded recently. Prior to that I had no problems accessing everything.
ps. I've disabled Snort blocking just to eliminate it from suspicion. Snort is the only add-on package installed. Also switched to 8.8.8.8 and 8.8.4.4 to minimize the chances of this being a DNS issue, although the PFSense DNS Resolver is enabled (provides effective caching for most of my machines).
pps. Basic firewall health stats: