It's a slightly overcomplex setup with several VDOMs. On the other hand that made it really easy to separate out the one subnet that has a default route out over an IPSEC tunnel (whereas the other networks route out directly on the local DSL line).
Did not manage to throw that in a single OPNsense setup in a working way up to now, and there don't seem to be any options to create VRFs...