I think the problem is that only ports 111 and 2049 are being allowed
by the current ruleset, and the other necessary ports for NFS (which
rpcinfo -p will show, and the link I posted shows how to control) are
still closed.

To verify this, check the output of rpcinfo and look for the port
entries for status, mountd, rquotad, and lockmgr. Create firewall
rules which ACCEPT these ports (udp/tcp per rpcinfo) and restart the
firewall without restarting NFS. You should now be able to connect to
the exported volume from your client.

