The vpn policy (allowing to use vpn for specific mac address) is for outgoing traffic.
For port forword, you need to set up for each device. If you do not set up portfoward for one server, it is not accessible.