Get a Protectli box with a very good CPU, 4 Ethernet ports, install OPNSense, and have at it.
I'm surprised the UDM Pro cannot route 2x 1 Gbps on two WANs. I thought it was rated higher than that.
Your test might be running into the 1 Gbps limit backplane problem on the built in switch for UDM Pros.
With your setup, if two devices want to communicate, and their ports and the ports on the switches they connect to all supports 10G, then they'll communicate at 10G.
If any of the ports is 1G, even if every other port is 10G, it'll drop down to 1G for that particular communication pathway. That drop down does not "spread" to other pathways.
Having a 1G device plugged into a 10G switch does NOT affect anything else on that switch. Each connection has the "right" to connect at 10G as long as everything along the communication pathway supports it, and is not affected by other concurrent connections that are happening alongside it. Switches can compartmentalize each connection as its own.