Remove masquerade.
Remove this forwarding, you have the wifi->vpnfirewall already.
MS-V is the only one that works because the default gateway in the routing table is from the vpn, but you don't allow (and don't want) that in firewall.
You need to do Policy Based Routing and you have 3 options:
- mwan3 package
- pbr package
- a set of rules/routes for each internet connection.