I created a rule to prevent WAN from accessing my camera, but the rule seem to be ignored. I can still access it while on my 5G cell connection. I'm not connected to VPN server. Is this a bug?
I would assume that the camera talks to WAN, not the other way around.
Since the firewall is stateful, it won't block the connection then. You would need to block WAN access from the camera as well.
If you don't forward a camera port from your public IP to your private IP, no one from outside can access your camera.
If you think this isn't the case because you're using an app to connect to the camera (it may have cloud services), then you should block the camera's internet access. Therefore, your rule is backwards: LAN source, WAN destination.