@serbus John, your bottom rule in the PRI list is redundant. It's saying that on your PRI interface, to block any source to any destination over any port. It's also got zero states with zero traffic.
Your 2 PRI to WAN rules can be summed up with a single rule - protocol both IPv4 and IPv6, source PRI net to any destination.
Quick question - are there any hosts on this PRI interface, since none of the rules have any hits on them? Looks kinda like a ghost town. What is the PRI network, a guest network?
Your PRI to LAN block rule would never get hit, unless you've got IPv6 running on your network. You have an allow rule directly above your block rule, first rule to match wins, no other rules below are evaluated.
Hope that helps a little... :)
Jeff