Circling back here.. it turns out, the issue was that the newly reserved internal IP addresses weren't getting the network tags fast enough and/or the firewall policy was not detecting them fast enough. Modifying the firewall rule to allow the entire CIDR ip range so that it no longer relies on the network tags did the trick. Haven't had a single hiccup since that change.