The port-forward tab you're using is only for simple setups, when only a single WAN/single IP address is involved.
Because of the VPN, you sort of have 2 WAN interfaces.
The extra portforward you created has opened up your SYnology on the WAN, not on openVPN link !
Replace the synology portforward to a dNAT rule. (I'd prefer to convert all port forwards to dNAT