@bigtfromaz you could maybe limit the outbound nat for only the device you would be coming from lan with. Like your pc... But yeah that works..
If you just add the route as persistent it should survive reboots, upgrades, etc. you shouldn't need a batch to kick off on startup.
I would normally allow ping as a way to validate connectivity..