Good info but I can’t run wireguard on my router (older os on arm64 there is no wireguard binary) until I replace the router so only openvpn for now, thus your suggestion won’t work for me at this time.

I tried setting vpn policy did not solve the routing issue. Maybe it only works for wireguard?

I will be replacing my router next couple months so I guess since this won’t be trivial I’ll just wait till then.