SOLVED - I figured out my problem. It was caused by this setting below (Static ARP under the DHCP Server configuration for the interface), which I had enabled on the interface because I interpreted it incorrectly. It essentially took precedence over any and all allow rules configured for the OPT2 interface, and prevented any host without a statically assigned DHCP address from communicating with the interface even though the host received the dynamic DHCP assignment from the OPT2 interface. I hope this saves other folks time and headache.
[image: 1573105135994-screen-shot-2019-11-06-at-9.46.34-pm.png]
As explained in docs.netgate[.]com[image: 1573105210701-screen-shot-2019-11-06-at-10.40.04-pm.png]