Hi,
If you change the INPUT to ACCEPT in vpn_zone you should be able to access MiFi remotely, but the route/firewall will be complicated if you also want to access its clients. I think it will be easier with tap mode.