@johnpoz
Who said I am applying the rule on lan?
I'm aware interface rules are ingress only, sure.
Here's screenshot from netgate recommendation illustrating the floating rule on WAN
1000119912.png
Now, with that rule, as the doc says, you need an allow rule before it. The thing is that the allow rule must apply to all interfaces the filtered packet travels through and not only Wan
I suppose it is a strict security that the stateful inspection needs to track the packet through all its lifespan