I've created a firewall rule on OPT1 *|*|*|*|*
This will only allow traffic from the OPT1 network to the LAN not the other way round, which is exactly what you were finding
I can ping 192.168.35.2 from the diagnostics>Ping/Traceroute utility if i use the OPT1 interface, but I can't ping 192.168.35.2 from client1
I can ping 192.168.35.205 from client1, but nothing else on the 35.X network.
The rules act on the interface where the traffic comes in on, so you need a rule on both interfaces allowing traffic to the other network.