[Solved] Safely and permanently open LuCI 443 and SSH to WAN

You can do it in LuCI (network > firewall > traffic rules).

As for vpn, check out wireguard. Simple to setup and high performance. OpenVPN is also not too bad, but less performant and requires more work to setup.