Mikrotik And Starlink Port Forwarding Question

To clarify.

Standard VPN functionality requires you to have a publicly accessible IP, not the case with Starlink.
Thus you cannot use your router as the HOME BASE for VPN like wireguard

Therefore you have to use an external HOME Base for the VPN, it could be another location (relative, friends house) or a third party provider or hosting your own at a datacenter.
There is nothing stopping the MT behind starlink from connecting OUTBOUND to make a wireguard or VPN connection. It just cannot HOST any inbound connections with VPN.

Zerotier (requires arm) gets around this in a way because it uses the third party concept alluded to above. The HOME is in the cloud so to speak. It, like wg is an available options package for arm devices.

Yes, RB4011 is arm32 device.
http://forum.mikrotik.com/t/zerotier-on-mikrotik-a-rosetta-stone-v7-1-1/155978/1