What setup is needed to route traffic from selected devices behind a Google Wifi NAT through a VPN tunnel?

Hi everyone, as the title says, I’m trying to send traffic from a couple of devices behind my Google Wifi NAT through a wireguard VPN tunnel. I’m looking for advice on how to solve that problem.

Here is my current setup:
topology.png
I have a DMZ set up where routing traffic from Wired Device 1 through the Wireguard Tunnel is working perfectly. However, because of the Google Wifi NAT, I’m not sure how to accomplish the same for Wifi Device 3 because I can’t see its IP address.

Some questions:

  1. Is there a configuration change I could make on the MT Hex to enable only Wifi Device 3 to go through the VPN tunnel?
  2. If the answer to #1 is no, then what’s the simplest/best approach I could take given the topology I have? I have an extra Hap AC sitting around. Is it possible to put the Hap AC behind the Google Mesh Wifi, and set up an Ethernet-Over-IP tunnel between the two MT routers and send Wifi Device 3’s traffic through that? (something similar to this post?)
  3. Is there a better solution?

Thank you in advance! Happy to provide any more details about my configuration if they’re needed to answer my question.