@gwaitsi

the client on vlan20 can ping all switches, routers and the firewall on vlan1 - but not the ipmi port
the routers and the switches can ping all devices including the ipmi port
pfsense can ping all routers, switches and clients - but not the ipmi port
there is no inter-vlan routing on the switches, everything must go through pfsense.
rule specifically allows all protocols / addresses from vlan20 to vlan1 and rule for vlan1 to vlan20 (for eliminating rules as a source)
the test results are also the same if i put the IPMI port into the openwrt with untagged vlan1 port instead of the managed switch
i don't understand why pfsense can't talk to this one device, when it can to all the others on the same network.
** to eliminate all possibilities, i put the ipmi port on the same vlan as the client on a openwrt port set to untagged. It was then able to get a dhcp from the client vlan