Kb8wfh,
A couple of things that helped me(and continue to help me) are:
making sure to look in your firewall logs to see what is being blocked
attached are my rules I have on my wifi interface, they are fairly hardened, I sense you are trying to do the same. It might not work for you…FYI - your LAN rules basically allow everything, rule 1 isn't doing anything that rule 2 would do. Try to understand my rules vs just copying them.
when writing a rule, go into "Advanced settings" and you can pick a "gateway" i.e. Either WAN or PIA. I use this vs changing my default gateway
get to know "easy rules" that can be turned on in your firewall log, it will add what was being blocked, you can modify these easy rules but it helped me understand the flow of data. Make sure to possibly change the order of the rule in your interface if necessary.
make an alias for your Apple tv and WAN only devices (notice in my rules I have SEVLAN as a source, these are aliases I set up after setting up fixed dhcp leases), make rules allowing access using the alias as the "source", in advanced setting for those rules use the WAN.
Dig into your log(NAT or Firewall), I suspect you'll see what's going on....
(As mentioned by someone else, your dashboard is showing your PIA as offline, dig into your gateway settings for PIA and look for the field for "monitoring IP", use googles 8.8.8.8 as the monitoring IP...I had that issue as well and was fixed with adding a google monitoring ip)
[image: IMG_0042.PNG]
[image: IMG_0042.PNG_thumb]