@Wolf666:
With pfSense, you can setup rules in order to route specific IP to use VPN only. So, map as static IP any client you need to be routed through VPN. Set outbound and firewall rules accordingly.
If you want, like me, build a separate subnet, dedicated to VPN. You can also use VLAN approach.
As VPN provider I suggest AirVPN.
Wolf666, thank you for the ideas and VPN suggestion