Hi, I'm pretty sure that is the same issue here, I posted a screenshot of the WAN->LAN rule (+divert-to Suricata, and DNAT rule).
Here you can see the screenshot, the same rule is blocking and passing the traffic.
https://forum.opnsense.org/index.php?topic=52395.0
Here you can see the screenshot, the same rule is blocking and passing the traffic.
https://forum.opnsense.org/index.php?topic=52395.0
"