Thanks, I think there are benefits for specifying by interface as you may not want to use VPN on your home network since it's already secure, but may want to on a backup network, such as celluar or public wifi.

For the configuration:

I see on the Firewall Zone configuration that wgclient and ovpnclient is already forwarding to wan.

Should a new zone be created specifically for the vpn clients that forwards to wwan and tethering?