This is how I would have redirected any DNS requests not going to my Firewall, but instead redirect those requests to Cloudflare's DNS (1.1.1.1).
So it would appear that if the port forward is listening on the LAN, it cannot redirect to and an address on the WAN. I should add that I have recently switched to Opnsense from Pfsense. I had the same issue on Pfsense but did not have to resolve it until now.