OK, I got it. Sort of. I made ports 2,3 and 4 vlan 2 and ports 1 and 5 default, 1. Port 1 is the OPNsense and port 5 is the AP. 2,3 and 4 connect to the firewall on a separate ethernet port and are in the 192.168.7.1/24 subnet. Not exactly how I wanted it, but it does work to have my security...