and to make sure the return information from apache can make it back out the same way
your AWS opnsense NATs the traffic that goes to the VM to its own VPN IP (or another one that will be routed from the VM to the aws opn), so the VM will send the response to the aws opn back (here it will be translated back to the original public IP)