I checked and I think it is the same as our.
There is only one forward rule like this. No data is forwarded to WAN so this is how data will not goes to WAN. If you don’t check “force vpn” in our web UI, data will Masquerade in WAN.
config forwarding
option dest 'ipr'
option src 'lan'