However, the router web UI at Firewall's address for LAN_TEST_00 is still accessible a computer on LAN_MAIN_00.
This is probably due to the automatic "anti lockout rule" that does some weird things with NAT port forwarding to ensure access to the UI. I disable that in all my OPNsense installations and rely on proper manual rules for UI access.Your rule does work for TCP, don't worry. The UI is what is "special".