Internet --- ISP router ---(WAN interface)--- opnSense Firewall ---(LAN interface)--- Router --- ... | DMZ
Translation target for the outbound NAT rule is "Interface address", static port shouldn't be required. Other than that, sounds good. 👍