Thanks for the clarification…with the idea that “more is beter”, for now I am going with:

LAN: A,A,R (input,output,forward)

WAN: R,A,R with Masquerading enabled

VPN: R,A,R with Masquerading

I will report back with any problems, if any.

Glitch