┌────────────┐ ┌─────────────┐ ┌────────────┐│ VM ├────────►│ Router ├──────────►│ Internet ││ 1.2.3.4 │ │ 10.234.0.1 │ │ 8.8.8.8 ││ │ x───┼ ◄───────────┤ │└────────────┘ └─────────────┘ └────────────┘
Assign the first address of that subnet to an interface of OPNsense, e.g. OPT1. Connect VMs to that interface, give VMs the remaining IP addresses with the OPNsense address as the default gateway. Disable NAT.While RFC 1918 did introduce a concept of "public" and "private" IP addresses, nowhere does it say, that public ones must be placed on a "WAN" interface. And proxy ARP is evil.Just configure your interfaces and let routing do its magic.