Update: ditched the second OpnSense and figured out that MTU discovery with PVE and stuff needs some hard tweeking. Got it to work now. Hit me up for guidance 😅
What? That's totally confusing. Took my Laptop (192.168.35.242), tethered to my Mobile (192.168.35.116) and wiresharked. 192.168.35.0/24 should never ever be a part of my Network.
At a time I tried to use two proxies but I changed it back to one. The host I try to reach is a Docker Host with Immich running. So the only real proxy should be "192.168.1.1".
There is one DNAT rule at the public OPNsense routing the HTTP/s traffic to my proxy. Inside my DMZ an LAN is no NAT, only routing. Back out again there is a Masq/SNAT rule for my local IPs
Update: ditched the second OpnSense and figured out that MTU discovery with PVE and stuff needs some hard tweeking. Got it to work now. Hit me up for guidance 😅