Remote Shack with Expert Remote 

'all-in-one-place' practical setup guide
Expand Remote Shack network further (when ready)
The good thing about the Remote Shack setup described in this guide, its basic netowrk is fully ready for expansion. When the time will come to add extra networks equipment (i.e. network-enabled PA, AC/DC Power management system, Antenna switch, Rotator control, etc.), it will not require full reconfiguration, just small easy modifications and add-ons. Potential add-ons are described below.

External Network Switch
(tested) First thing to decide: how many extra wired network ports needed, because this will determine the port count of the network switch to be added. In regards to brands, you can easisily start with cheapest models on TP-Link, Netgear or similar, (like 5-port TL-SG105E, 5-port GS305E or 8-port TL-SG108E, GS305E, or choose PoE/PoE+ models if needed).

In described setup there is only one "spare" port. The answer to the question "can I use this port to add small SOHO switch" might be "yes" and "no", dependent on the tasks you want to achieve at the end. Generally speaking, having Mini-PC ETH1-3 switch-grooped and plug external network switch into this group is not recommeded, however in some simplistic Remote Shack scenarios it can work fine - but require extra attention to configuration and intensive testing.

Alternatively, and if you want to use best recommented practices, then you may need to remove the opnSense switch group (returning it to individual port defaut config) and plug into (say) ETH1 the external network switch with enough network port count. Even smallest external network switch models (mentioned above or similar) are supporting VLANs and .1Q trunking (if those will be needed by your future design) and fully compatible with opnSense, configured in the context of Remote Shack purposes.

opnSense configuration changes
This part assumes you will need to expand your knowledge of opnSenseIn vast majority of the topologies and scenatios, the opnSense config will be simple, i.e. ungroupping Bridge and reconfigure any of physical ETH ports to defauls, or creating VLANs, or creating .1Q trunks are all very well described in official opnSense documentation.

Expert Remote fucntionality upgrades
and options are explained in the next section.
BACK NEXT