yes vpn is a problem.
When you turn on vpn client on MT300N-V2, you can port forward from your Asus to it.

But you cannot port forward to its client easily because of vpn firewall. Actually you can do this be setting up in luci. But there is a lot of interfaces so I am afraid this will break the vpn anyway.