tailscale up --advertise-routes=192.168.2.0/24 --advertise-exit-node --accept-dns=false --accept-routes
as you alreaday found out there are many articales and videos about implementing such tunnel.Important for pfSense/OPNsense is still the opening of the tunnel for needed port 80/443 to let traffic in which can be forgotten for normal routing usage.Did you allso found this direct configuration guide?https://tailscale.com/kb/1097/install-opnsense
sudo headscale routes enable -r ROUTE ID
sudo headscale routes list