If set up properly, devices using the VPN will appear as devices on the local network. Therefore the WAN address setting in BI will have no bearing. Personally I think it should be turned off just to ensure it won't accept outside connections.
That being said, BI will allow you to "limit" the LAN connections to a specific set of IP addresses. It's possible that this is turned on and preventing the VPN devices from connecting. While devices using the VPN will appear as locally connected devices, they are generally NOT on the same IP address scheme as the rest of the local devices. So if your actual local network uses 192.168.1.X address scheme, the VPN connections will have a different set of addresses (perhaps 10.0.0.x). Therefore it is important to make sure that either BI's local LAN settings aren't filtering addresses, or you have added the VPN addresses to the filtering settings to ensure they are included.