Hey. As I can see, you using NAT and also you have global IP address on your WAN interface. If so, then you just need to create one destination nat rule to this single host with /32 mask. But don’t forget to configure your VM from inside in order to deny any conenctions from VM source IP to your LAN devices except direction your user need to.