Wireguard. Wireguard is fairly easy to configure and keeping your setup behind the firewall is much less headache in the long run.
First rule of hosting publicly available services is “Don’t. Unless you absolutely have to.” Second rule is: “If you have to, do it very carefully.”
Yep. Split tunneling has been a standard option for a long time.