As ever, thank you alzhao for taking the time to reply!
This is one of quite a few articles that I found: Njalla — IPredator is moving to Njalla
Specifically, look under “Firewall zones” and Interface and Firewall overview"
The line that particularly caught my eye was “Traffic from the lan zone is only allowed to exit masqueraded through the ipr zone. Masquerading on the wan zone is disabled.”