I could do this, but I would need to create rules for each OpenVPN interface because each one gets access to a different LAN subnet.
Seriously, if you want fine grained control, the firewall rules are where you enforce it. There is no higher level abstraction in OPNsense.