I think OP has already got OpenVPN working from a remote location, by setting the ISP router to give a fixed IP address to his RT-AC86U which is running OpenVPN server, and forwarding port 1194 on the ISP router.
So no need for any configuration changes or DMZ - just bring the RT-AC86U router downstairs right next to the ISP router, and plug the Asus's WAN port into one of the ISP router's LAN ports.
OP, if you need several connections upstairs, you could use your old RT-N66U (I think you still have it?) as an Access Point upstairs, with its WAN port connected to the RT-AC86U downstairs over the powerline connection. Your clients upstairs can connect to the RT-N66U both by radio and with ethernet cables. If this works fast enough for you, there's no need to buy a switch.