The router Web UI is only for port forwarding through WAN. I am not really sure how I would go about such a solution in IPTABLES .
What I'm thinking there is there is an interface on the router from which VPN packets "appear" from incoming connections
and that interface has a known ip address, and is persistent, and is local.
But I don't know how packets get routed to the bridge interface though and I wonder if that routing is setup by the VPN client starting up, it looks like there's only routing for outgoing traffic.
It may also be needed to add filter rules to match packets coming in and going out of that local VPN interface for those apparently non-existent routes to do what's needed.