Far gateway should help, or place a router/modem infront and run private IPs und the OPNsense where the router portforward all ports to the the HA IP internally