Rereading your replies…
To be clear the traffic from pfsense to mikrotik is over a single port.
This traffic is it TAGGED vlan3 or is it arriving untagged??
You have six pools dhpc etc.
BUT NINE vlans, and SEVEN of those are bridge
why two vlans not on bridge???
why seven addresses? nothing adds up.
If you indeed have seven data vlans, they should be all on the bridge.
Even if one of them is vlan3 coming from the pfsense, either tagged or untagged for that matter.
There should be six pools/addresses/dhcp for the six data vlans, and one address for the pfsense vlan
There should be three interface lists
wan VLAN3
lan - all six data vlans
trusted → used for the vlan3 where the MT gets its internet address from
+++++++++++++++++++++++++++++++++++++++++++++++++++++
Use this as a guide, THERE IS NO BRIDGE DHCP etc, all done via vlans.
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1