@Derelict
You made it clear enough: "The webgui always listens on all interfaces."
This morning: backup, disable LAN, and... YES: I still have GUI access from Cisco over trunk, direct from OPT1, (and temporarily direct from from WAN).
I'm in GUI from WAN (static at 192.168.8.1)
FW rules on WAN:
Pass IPv4 TCP 192.168.8.202 * This Firewall 443 HTTPS * none TEMP GUI over WAN
Pass IPv4 ICMPany 192.168.8.202 * This Firewall * * none TEMP Ping over WAN
Modify the TCP rule replacing
This Firewall
with
Single host or alias: 192.168.8.1
and it works (as you said it should).
Sorry to have troubled you. I'm switching between nine different IPs on my laptop -- must have been "doing it wrong" when I lost GUI on OPT1 during my experiments.
Thanks, Chris