How do I make it so that no site is accessible on the WAN IP
Separately is it possible to have the NGINX part of OPNsense running off an additional WAN virtual IP i have?
Nope unfortunately that was first thing i tried
here are FW rules on WAN if that helps get a better idea