Indeed, it seems if masquerading is disabled on the WAN, the input has to be “accept” (this was the recommended setting from my VPN provider).

Thats was the crux of my original query - ie. what is the difference between:

WAN: A,A,R versus R,A,R with Masquerading enabled

Seems like the answer is nothing, or at least, not much!