I have been struggling for weeks.
Have broke a laptop throwing it across the room, and have essentially broken my fist.
I am at my wits end.
OPT1, all traffic needs to go over VPN_DHCP. every rule I have tried does not work. ONLY opt1. thats it. It shouldnt be this hard.
the VPN interface is up. its a stupid rule somewhere. I dont get it. so frustated and discouraged.
If I understood your configuration correctly, then all you need is a allow any rule on OPT1 with "VPN_DHCP" (assuming this is the VPN gateway) set as your gateway and an outbound NAT rule for the VPN interface with "OPT1 network" as source and "Interface address" as translation/target.