You should use mac based policy and use vpn only for the Minor.
But for Helium, the most important is to do the portforward via the vpn to the lan. You didn’t mention this part.