I agree that it feels like a pfSense config thing, but I don't know enough about it to recognize the issue. But before I went back to junk consumer stuff I'd format, reinstall, and reconfigure the Netgate using the latest version of pfSense.
Separately, does the PiHole run on the Netgate? What...