Remove all of your reverse-SNAT rules. They are automagically handled implicitly. Can you receive the packets from the server? Does the server's default route take it back through the firewall? Does the firewall detect the reply packets on the inside interface? Does the firewall detect the reply packets on the outside interface?