Well, that depends. Do you want to be able to access the Ewon from the WAN (plant network)? If so, set to allow all (2). If not, you can leave it at (3) and just accept VPN traffic and ping. This doesn’t effect the VPN connection though. It sounds like you have another problem altogether.
Can you try setting the DNS servers in the Internet Wizard to public DNS servers, like 8.8.8.8 and 1.1.1.1? I see that they are set now to DNS servers on the private network in another subnet. Maybe they can’t be reached.
Do you know if your company has made any changes to the security (firewall, proxy, etc.) of the network recently?