I got it. It's as simple as this: you can't use "advertise exit node" and "use exit node" at the same time. You still need to configure the hybrid outbound rule, the Tailscale interface as the gateway, and route the traffic using policies — and that's it, it works!
Just keep in mind that if you want your network to be routed through a remote exit node on your tailnet, you must disable "advertise exit node" on your OPNsense. You can switch it on and off whenever you want, but you can't have both enabled at the same time.
Just keep in mind that if you want your network to be routed through a remote exit node on your tailnet, you must disable "advertise exit node" on your OPNsense. You can switch it on and off whenever you want, but you can't have both enabled at the same time.
"