Selective Remote Access
-
If you intend, that PLEX2 upstream traffic goes out on the WAN interface independently from the vpn client connection, that's okay.
If I change the gateway on the Plex2 rule from WAN to default I can't get out to the internet. Not sure why default doesn't work but it still works with the gateway as WAN.
Had to add a path back to the LAN when I connect as the USER so I could access the other servers. All others in the Plex only alias can only connect to the Plex Server and internet through the WAN gateway.
Here is the final Plex2 rules. Thanks again for your help.

 -
If I change the gateway on the Plex2 rule from WAN to default I can't get out to the internet. Not sure why default doesn't work but it still works with the gateway as WAN.
I've mentioned that behaviour and the solution alreade twice.
here: https://forum.pfsense.org/index.php?topic=132341.msg733209#msg733209
and here: https://forum.pfsense.org/index.php?topic=132341.msg732814#msg732814So what are the troubles with that?
If your vpn client connection is up, the packets go out this connection, when there's no gateway specified in the appropriate rule. So you also need to add an outbound NAT rule for this traffic (on the vpn clients interface!). How to do, I've described here: https://forum.pfsense.org/index.php?topic=132341.msg733440#msg733440