I think I found the culprit but I can't test right now because I have an appointment. I think it's DynDNS on my NAS. The IP behind its DynDNS domain changes to the public IP of my VPN server. This means clients from the internet try to access my NAS through the VPN tunnel which of course blocks the connection. Gotta do some testing later.
The screenshot shows only the LAN rules. The interesting part would be the WAN rules.