Port forward Plex server behind NordVPN

I'm trying to config a Plex server port forward on my GL-MT6000 where I'm also running NordVPN client in OpenVPN UDP mode.

Plex only sees its public facing IP as one of the Nord datacenters.

I've tried sticking the Plex server in the DMZ but it appears that as soon as that tunnel is up everything behind it routes out over the tunnel.

Is there a way I can bypass that Nord tunnel inbound/outbound for this Plex server, ideally only its NAT port directly from the WAN interface? Leaving everything else protected behind that NordVPN?

Thanks,

Tim

Figured this out. Changed the VPN policy to be based on client device and then set the plex server MAC address to "do not use VPN".

Not quite as elegant as I wanted, but I have other machines on the network running zerotier that I can RDP in remotely/safely.