The other problem though with your setup is that it appears your tunnel IPs are overlapping with your local network - 10.98.x.x is within 10.0.0.0/8. That won't work. The tunnel subnet must be unique, ie not a subnet otherwise used on OPNsense.