You mean port forward from WAN to LAN, not from VPN to LAN right?

As far as I know, when you use vpn for all devices, port forward from wan to lan does not work. You must enable vpn policy to make it work.

So seems you are saying the exact contrary.