short answer: no. long answer: no, because the talk directly, opnsense not involved (special case: wifi). get an additional interface and place devices to be separated in different subnets attached to different interfaces.