This makes a lot of sense. I could not wrap my head around the last statement. How would opnsense recognize vlans on trunk port without having a vlan-aware bridge? I'm my current setup, I have WAN comes to NIC0 on the VM, then LAN/VLANs leave tagged through NIC1 to the trunk port on the switch...