The last rule is obsolete because LAN-to-LAN traffic is handled by your switch and not by the router (OPNsense in this case).