Your pic shows NAT outbound rules, you also need pass rules on each interface:On LAN interface, create a pass rule with destination: !(not) This firewall, gateway: WAN.Create a same rule on LAN2 interface, except with gateway: VPNWAN.