The quality of the response is directly proportional to the quality of information provided to elicit a response.
Its not your fault, that the MT barons, do not have a quality standard of posting, avoiding first posts bereft of facts.
To better understand your situation, it would be best to provide
a. your config /export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, etc.)
b. a network diagram showing topology ( which devices are involved what internet connections are involved, what subnets are flowing over which ports )
( provides your visual plan )
c. Finally a set of requirements to that the config can be measured as to meeting requirements and to avoid conflicts in advice....
i. identify all users/devices including the admin
ii. identify all the traffic flows required by users/devices.
Over to you, since my crystal ball is in the shop for repairs.