Your case looks more like your OPNsense is internet facing and in that case, you don't have to mess with real IP source at all. The real IP address should be just forwarded to the backend by default (using the industry standard x-forwarded-for).
Using the internal OPNSense Dnsmasq service I created a DNS entry for the subdomain test.example.org pointing to the IP address 10.68.0.1, which is an internal (VLAN) interface of the OPNSense.