Thanks for the clarification…with the idea that “more is beter”, for now I am going with:
LAN: A,A,R (input,output,forward)
WAN: R,A,R with Masquerading enabled
VPN: R,A,R with Masquerading
I will report back with any problems, if any.
Glitch