You were right Mr vgaetera, Zerotier worked like a swish watch crossing my 2 4G ISP cg-Nats in Spain, and I now can finally view my IPCams located in the village supported by a fast Youku YK-L1 OpenWrt small Router with just a simple USB Dongle plugged for the internet, FROM my Android phone in almost any region of Spain.
In my country IPv6 for almost all 3G/4G/5G providers is expected for future years, but not now.
Price is the barrier for all and 5€ month for just 4Gb of 4G overall internet transfer is the more afordable option here, to have internet in a rustic place with NOTHING ELSE source achive connection (as a remote village) . A poor user as me has to pay another 5€ month for the second SIM in the android phone, RESULTING 10€ month overall cost of the REAL site to site MINIMAL self depending infraestructure (no free wifi from others) -> low quote ALSO MEANS cg-Nat to face with.
I would have been happy to follow your suggestion of "BUY a cheap VPS" to be able to try Wireguard working WAN to WAN, but all I found was RENTING VPS providers with minimal 3€ month cost.
To be honest I found a "only in theory" free VPS from Google Free Tier, but "NOT IN PRACTICE" for me, because THEY REFUSED my Mastercard Credit Card with the excuse "it is not an extrict CREDIT card" (those exposing bank accounts) , as mine is a "prepaid" Credit Card (those with balance to reload) . So they refused the account proccess with that excuse, in spite they promise NEVER will take funds of the "DISCRIMINATING" Credit Card they want.
Oracle offers a similar free VPS VM option with also Credit Card condition , but thinking I would finally find previous situation -> I DIDN'T Try.
Marvelous Joe Ramirez Blog Post about cg-Nat and Google "free" had for me the Credit Card trap and couldn't be tried.
So finally I followed Mr Warning clear steps:
I was only familiar with the green "LAN" and red "WAN" zones in luci, so the new brown "VPN" custom zone in "unmanaged" protocol was intimidating.
It took me 2 days to get it working, the first day only got TX packets out in luci (RX always 0), same situation as I had with WireGuard installed before I opened this topic.
The hardest to get finally RX packets scoring was in ZeroTier web control panel -> I had to click the "bone" icon in "members" row to get displayed the purple area with "Allow Ethernet Bridging" THAT MUST BE CHECKED (in Router member and also in Android member too) .THAT WAS THE MIRACLE to get RX working finally in router.
But so much effort had the reward -> CAMS are fastly displayed now in the Android phone just writing in Chrome Browser of Android the 192.168.1.10x:88 of local cam web server plugged to Router in the other side hundreds of kilometers away in the remote LAN.
Most modern IPCams don't allow direct video in browsers so easy, but classic Wancam HW0024 IPCam allows this in low cga video format from a mobile.
The real problem "that created the necessity for me" last year was that Wancams bastards stopped in 2020 supporting the previously promised "forever dns service" and remotely viewing for their cameras by PC or by phone by E-View7 became IMPOSSIBLE. E-View7 app literally DIED in phones (and it was even removed from Google Play).
With Zerotier I could revive this old cameras.
2 options untested by me that I also found in the way:
1 -> ngrok
2 -> tailscale
I decided not to test any of them because I think they are not so well documented for OpenWrt as ZeroTier is.
ngrok has good press, but I think there is not a package for OpenWrt and only a github option to implement it by ssh. Even bringing it to work in an Openwrt Router with devices plugged in LAN, it has the defect that clients must receive a public key that system creates every time the router is rebooted. That made me skip to try it.
What I have understood about Tailscale is that they of use internally WireGuard and they offer their Corporation web servers in a free limited option for the users for site to site connections working through cgNats. Even found an ENORMUS PACKAGE (really 2 packages) that have been reported working in some OpenWrt Routers with lot of free Ram (as my Youku has) , but not so well documented as Mr Warning did with ZeroTier.
¿Any comment about if it could be possible to get working the enormus Tailscale package group in OpenWrt and luci in a similar way as Mr Warning did with KeroTier -> creating a "TS" interface by "Unmanaged" protocol and with special "VPN" zone?
Thanks Mr. vgaetera.