Help with MikroTik CRS309, VLAN, trunk/bond, untagged traffic, etc

Also no specific knowledge of the Mikrotik kit but;

untagged traffic over LACP link - Start tagging your main subnet with a vlan, it will be a bit of a pain in the arse to get all of the management vlans switched over but it will mean that all your traffic is tagged and your problem goes away.

vlan 50 being firewalled - Even if the switch does provide some form of firewall it will be so basic that you either might as well just pass vlan50 straight through to pfsense and have it route out or you will need to pass it through to pfsense to get the firewall flexibility to do what you need. I may be massively underestimating the CRS309 here I guess.

As a side question, is the Dell struggling to cope with the load or are you just doing it to pay?