Right so had a rummage in the log files and worked out what the problem was.
Block Sep 8 15:41:43 WAN xxx.xxx.xx.xx:535 172.16.0.244:80
The port-forwarding rules that I had setup in NAT were only allowing connections from the "interface address" ie. the real ip of gateway-1 or gateway-2's Wan interface.
Selected to allow from the wan-carp interface "172.16.0.244" and all is now working well.
Sorry for spamming forum, hopefully someone might find it useful at some point.