Welcome back!
I'm going to guess that it is your use of the
egress group in your nat-to rule. If the carp(4) interface is not part of the
egress group, then this rule will not apply. And, normally, carp(4) interfaces are part of the
carp group.
It's just a guess, of course.
----
Edited to add: the
egress group is assigned to interfaces that use the default route. So if this is the problem, you may have a routing issue via the carp(4) interface.