RESOLVED
I always figure it out in the end.
Right so what i misunderstood was on the Opnsense plugin in order to apply the flag --exit-node-allow-lan-access
you can't advertise Opnsense as an exit node at same time, so I disable Opnsense as exit node and now all LAN devices behind the Opnsense tail-scale Subnet router now route over the VPN tunnel and use the far exit node as a gateway
			I always figure it out in the end.
Right so what i misunderstood was on the Opnsense plugin in order to apply the flag --exit-node-allow-lan-access
you can't advertise Opnsense as an exit node at same time, so I disable Opnsense as exit node and now all LAN devices behind the Opnsense tail-scale Subnet router now route over the VPN tunnel and use the far exit node as a gateway
"