yes, more precisely, traffic pass over the main pve ip which act as router nat.
But I'm wrong way, sorry, my head is too busy trying to write in english.
in Router NAT mode, VMs will not have a vpn ip itself, they can access other vpn ip but not the reverse : other vpn ips can't access vm, like...