3) Allow TCP Alias_IPS_For_GW1 to ANY DPort Alias-Ports(80,443) GW14) Allow TCP Alias_IPS_For_GW2 to ANY DPort Alias-Ports(80,443) GW2
1-2) Port FW rule, TCP/UDP, source (v)LANs, destination ANY destination port 53 - redirect to 127.0.0.1 port 53 (Unbound rule)
your second screen shot under DNS is empty..