You can achieve that really easily by enabling OpenVPN on ZS. You just open port 1194 on the firewall for the WAN connection. Then you add the networks that will be pushed to the client for the OpenVPN server, or you can assign them on your client configuration. This way if you want to just browse your network, you only add the subnet of your LAN to be injected in your client PC routing table. If you want to redirect all traffic through OpenVPN you add the default route in the client configuration and this way all your traffic goes through OpenVPN server.