Hi Chris -
I'll just chime in to answer your question as to why we don't have the ability to SNAT monitor traffic:
Monitor traffic is sourced from the non-floating self-IP for each unit in a redundant pair, since each unit will be performing its own independent health checks. (If a monitor instead used a floating address as a sourceIP, the standby box would never get a response, so all the nodes would be marked DOWN until after that unit became Active -- obviously not an ideal situation on failover for all nodes to be marked DOWN on the newly active unit.)
SNATs, on the other hand, are typically configured to use floating self-IPs (or SNAT-defined shared address) to maintain consistency on failover, so you would need to have a firewall rule allowing all 3 addresses to access the nodes.