Install AGH on your OPNsense? Or instead of a port forward just give clients the address of the Pi as their DNS server via DHCP.