No you just add a virtual IP alias to the WAN interface.https://docs.opnsense.org/manual/firewall_vip.html#ip-alias