Remote Shack with Expert Remote
'all-in-one-place' practical setup guide

and go to Expert Cloud to validate:

At this stage you do not need to create or modify any firewall rules - those already automatically created by opnSense, reflecting all configured interfaces. "Zero trust" policy automatically applied on all WAN inbound traffic, that means no connection allowed from external, unless it was requested from internal. This already existing configuration is more than sufficient for Remote Shack operations.
At later stage you may review the firewall rules and create new, if needed; or you can add VPN, etc. This need to be done carefully evaluating what you configure: for example limiting Starter to only connect Expert Cloud sounds secure, but this will stop TURN traffic. Hence - consider futher reading opnSense documentation and ask the community.
BACK NEXT