Well that isn't true at all. You can setup a Client VPN server with technologies like OpenVPN, Wireguard, etc, behind the firewall and forward ports through to the VPN server.
... View more
That sounds right. I agree they need to just let you make the static routes needed. They do have something called VPN exclusions now that might help in some situations. If only I could figure out a rule to exclude everything except a certain IP. Then it would be doable but a stupid way to do it.
... View more