It's not a good news. But many thanks for your testing.
Today, I updated pfsense to RC2h. And I made some tests and found some strange things. I hope it will help you to find the problem on IPSec at OPT1.
1. I disabled the IPSec and made below two tests, a and b.
a. DHCP on WAN and OPT1 - I can access Internet through OPT1 when I leave the LAN rule at default gateway.
b. Static on WAN and OPT1 - I cannot access Internet through OPT1 when I leave the LAN rule at default gateway. But I can access Internet after I change the LAN rule's gateway to OPT1's gateway.
2. I enabled the IPSec at OPT1.
a. DHCP on WAN and OPT1 with the LAN rule at default gateway - I cannot even see SPD on IPSec staus page.
b. Static on WAN and OPT1 with the LAN rule at default gateway - I cannot access to Internet. But I can see SPD on IPSec staus page and I found some IPSec logs that IPSec tried to establish tunnel and it failed. Below is the IPSec log.
Sep 3 02:21:57 racoon: ERROR: phase1 negotiation failed due to time up. 28cde7f46500a3aa:0000000000000000
Sep 3 02:21:28 racoon: INFO: delete phase 2 handler.
Sep 3 02:21:28 racoon: ERROR: phase2 negotiation failed due to time up waiting for phase1. ESP 210.109.xx.xx[0]->210.106.XX.XX[0]
Sep 3 02:20:57 racoon: phase1(agg I msg1): 0.102666
Sep 3 02:20:57 racoon: oakley_dh_generate(MODP768): 0.089224
Sep 3 02:20:57 racoon: INFO: begin Aggressive mode.
Sep 3 02:20:57 racoon: INFO: initiate new phase 1 negotiation: 210.106.xx.xx[500]<=>210.109.xx.xx[500]
Sep 3 02:20:57 racoon: INFO: IPsec-SA request for 210.109.xx.xx queued due to no phase1 found.
c. Static on WAN and OPT1. I changed the LAN rule's gateway OPT1's gateway - Now I can access to Internet through OPT1. And I can see SPD on IPSec status page. But I cannot find any logs that IPSec tried to establish tunnel even after I ping to remote subnet.
For more accurate test, all tests was made when WAN disconneted.
Thank you.