Out of interest, do you know why this rule is functioning correctly with the direction set to 'in'? I can't get my head round that. There's no traffic coming into LAN, it's already within it... or is this a total misconception?
Ah! That's got it, thanks! I thought the subnet would be the same as under the DHCP settings, but I think I get why it shouldn't be.. It was restricting every IP on the same subnet as the specified IP.