Portal interface are meant to accessed by humans who use web navigator devices.
xbox's shouldn't be on a network with such an interface.
Take down the portal interface or be ready to type son MAC's.
Better yet, slide in another NIC in yout pfSEnse box and make a OPTx 'xbox-only' network segment.
And before you ask: no, sorry, a filter like "Are you an xbox, then go ahead" doesn't exists.