@jriofrio
Just to corroborate your statement about (in my case) not need it to disable the hardware checksum with the intel x540.
You are correct, I enable it back and reboot the firewall, tested the connection of OPT1 (2nd LAN) and all works good, no problems accessing websites.
Also, I deleted the DoT rule for the 2nd LAN.
All good.. I'm please with the results.
PS: couldn't sleep , so i decided to do the changes now that no one is using the internet....