I tried to set 192.168.20.0/24 as a VLAN but then we had a problem on the smartphones because the VLAN must be tagged on OPNsense but smartphones do not have such option.
What do you mean you added a second LAN without any serious assignment?What does the full phone network config show?Do you have different filtering requirements for the phones, PBX, and other computers?
Assuming you're using WiFi for the phones and not OTG Ethernet, you set the VLAN on the AP's. Either by using multi-SSID or plugging them into a switch port with an untagged VLAN.Generally though, you should create NAT and access rules for your second subnet to connect to the internet if that's what you want. Unlike LAN, there are no default policies for additional networks.Bart...
You didn't answer all of my questions.
What does the full phone network config show?
Do you have different filtering requirements for the phones, PBX, and other computers?
Set the phone GW to 192.168.1.254
Another solution would be for you to change the subnet for your LAN to something larger than /24 if all you need is more IPs.
It seems like you're a bit out of your depth network wise and that this is for a business? I would recommend you either hire a Network Admin consultant or pick up an OPNSense support contract to help you get this set up.Thanks.