I’m not following the topology you are trying to create.
If the Beryl is operating as an openvpn client, with its wan port connected to the lan side of your router, then everything connected on the lan side of the Beryl is being tunneled through the router and your isp to the openvpn VPN server. I’m assuming the wan side of your router is connected to your isp’s modem. If you have two wan ports in the router, then is it some kind of failover?
Anyway, if you were to connect the LAN port on the Beryl to the WAN2 port on the router, you would be going in a circle, wouldn’t you?
If you are trying to have the router’s LAN connected through the tunnel, then you might connect the Beryl’s WAN port to the ISP modem, then connect its LAN port to a LAN port on your main router, make the main router an access point and turn off its DHCP.
EDIT: oops. Misread the model so ignore references to Beryl.