Yes, unless there is a compelling reason for TAP, always use TUN. If you want to use TAP, lie down until the mood passes.

Using the iPhone is a good way of seeing if your setup works, because your traffic unambiguously is going out to the internet one way and then coming back to your Orbi. If you take your Beryl someplace else and use the repeater (WISP) option instead, it all should work the same way.

Be aware that the speed at which you download something from the internet through your Orbi to your Beryl is going to be affected by your Orbi’s upload speed. At my house, I have a 200/40 cable connection, and at location #2 I have a 200/10 cable connection. So if I am reaching the internet through my house, I’m going to be limited by that 40.

For that reason, you may want to create a second Beryl VPN client, identical to the first, that includes pull-filter ignore redirect-gateway. If you use that second client, it should give you access to your home network, but any other traffic will go out through the Beryl’s own WAN, and not over the tunnel, because it will ignore the instruction from the server to redirect the Beryl’s gateway. So then other sites you will be limited to the 200, in my example. By having two clients, you can decide which mode you want to be in, everything over the tunnel, or only some things over the tunnel.