I'm stupid :D - just changed the firewall IP to .254 and it now works.. as the IP was being used by the interface. VM's can now access the internet and its being forwarded as it should.
I ended up referring to a user of the Facebook group finding the Opaque option that seems to be the only option working today for this!
The license value doesn't seem to be that big and it can be an option if it works well for my environment, so...