- on the LAN interface an inbound rule "Default allow LAN to any rule" (which I assume covers inter LAN communication).
Given your response, and reading up on it some more, it appears an inbound rule on the LAN interface will also influence the OPT interface's ingress in this way. And I presume this is all working becasue the first match/precedence hits this LAN allow rule before the floating "default deny all" that covers OPT.