If we don't filter any outbound packets in the OUTPUT chain (which by large part we don't), and we add an explicit rule to the input chain that says "accept TCP on port 12345", there seems to be no traffic-filtering value in conntracking the connections created (inbound to 12345), while there is a potentially large cost created (by the possibility of large conntracking tables, and having them fall over under various internal/external traffic scenarios).
Large conntrack tables have created problems before (which is why T105154 exists). Approx. ~70 of our ferm rules already include 'notrack', mostly internal services with large fan-in (e.g. rsyslog central servers).
The only upside is if we were planning on changing our OUTPUT default from ACCEPT to something else.