Asymmetric routing bad. Fix your routing. The state that goes into the state table for allowed connections/flows explicitly contains the interface. If a service can be reached via two interfaces in two different networks/VLANs/whatever - why go through the firewall in the first place?
What the föck is "antispoofing" and what makes you think than OPNsense has a feature like that?
ip verify unicast reverse-path
Again, anyone can answer my second questio (is there a way to circumvent the "asymmetric cut")?