Hmmm.. That's not what I would expect. Are you sure the web traffic is going through the tunnel? If you look at your public IP, does it show you the public IP of your opnsense router, or the router on your VPN?Why not try something like opendns? It's a free dns server that will allow you to customize blacklists and whitelists. Also does HTTPS filtering without MITM certificates.