syn_sent from devices connected to CRS109

Hello,

I have successfully setup routed VLAN using the examples mentioned here: https://wiki.mikrotik.com/wiki/Manual:CRS1xx/2xx_series_switches_examples and https://help.mikrotik.com/docs/pages/viewpage.action?pageId=103841836

Different machines within VLAN can connect to eachother, but none of them can connect to the internet (DNS is working).

If i generate traffic to the internet i can see it ending up to my opnsense, however when i open the capture i see that the packet are in error, only syn_sent is being received.
For each VLAN i needed to create a xx.xx.xx.227 ip address, if i set this address as gateway for the machines internet connectivity is working. I would rather have the gateways be to xx.xx.xx.1.
If i open a command prompt on the mikrotik, i can succesfully ping the gateways of the VLAN living on the pfsense which are xx.xx.xx.1

I have added a capture file, a drawing of my network and my config. Any help or input is highly appreciated.
netwerk.png
config.rsc (5.75 KB)
packetcapture_igb2_vlan111.zip (363 Bytes)

I removed the Mikrotik out of the network and replaced it with a common switch.
The problem persisted, i can only conclude it has to do with OpnSense, or the switch.

The switch did not receive as many updates as the OPNsense.

Anyhow, it is not a Mikrotik error. Thanks for anyone who took the time to look at my posting.