I guess the main question here is, do I need a double appliance setup like I have with the PfSense or should this be a supported setup within OPNSense, I moved to OPNSense as it is a newer FreeBSD which is supposed to support NAT on traffic through a VTI tunnel.