This option would only apply if the traffic would enter on the WAN and immediately leave again out the WAN.
Okey, and since the rules dont allow anything in from the WAN, nothing can enter either. Understand.
The LAN only have one rule. Its a * on everything and allow. =)
The subnet is not conneced psysical on any of the pfsence interfaces. The VLAN switch has a physical connection on the LAN side to one of our internal switches.