Could you please share the topology? How is everything connected? Also, please provide OpenVPN configurations from both, the server and the client.
If you configure everything correctly, there should be no need to use port-forwarding to reach your controller. But of course, if you do not want to route LAN networks via OpenVPN, then you can configure a port-forwarding rule on your RUT955 to redirect traffic to your controller.