@Hank, looks like you are looking to do split tunneling. I would this this when working from home such that I could utilize local resources (NAS, Printers et al) and VPN connected resources.

The split tunnel is configured on the client side (not the router side) and basically is just a routing table.

Googling a bit relating to my use of PFSense and IPSec; it involves forcing NAT transversal and splitting DNS.

I’ve seen some routers equipped with a button for NAT transversal, some doing it by default and some not doing it at all. (IE: there is some non nonsensical paranoia about using it sometimes).

I haven’t played much with OpenVPN much these days.