And to answer my own question, for some other poor soul that might search the forum for help. I forgot to add tagged switch ports 9 and 10 as described in documentation. So my tagged traffic was arriving to switch and staying on the switch never reaching the netgate core device.
Once I added ports 9 and 10 tagged in vlan config, everything worked
interface-vlan-config-to-work.png