I don't know what's happened but this problem (very slow GUI until rebooted) has gone away after I did a bunch of reconfiguring and cleaning up this morning. Since the problem seemed related to editing the firewall rules I deleted everything including the NATs and re-created all of the rules from scratch using exactly the same incantations
In the process I also moved the main Internet feed from Igb3 to Igb1 - the LAN side has always been on Igb0 with another Internet feed on Igb2. Igb1 used to be the main feed a while back but we changed providers and configured the new ISP on Igb3 - so for a while we've been running with internet access via Igb2 and Igb3 without using Igb1 at all - that's the configuration that was giving us problems.
The response time is now sweet and so far everything is running well.
So these are just questions for the developers to think about
1. Is there something magic about the interface called "WAN" that REQUIRES that it is present even if the firewall rules and configuration do not use it?
2. When an interface is deleted, what happens to the rules associated with the interface? I think they get left in place but since there's not interface associated with them you can't see them.