Sorry @Joel_w I really can't follow what you're asking. You talk about NAT (full cone or symmetric), "direct connection", port forwarding, UPnP. None of this has anything to do with TAILMON (Tailscale). Tailscale is a VPN.
Tailscale tries to create a direct connection between two units on the Tailnet, but NAT and firewalls can make that difficult or impossible. If it fails the connection is sent via a third server, a DERP. That’s slow so I’m trying to avoid that.
I guess my question doesn’t have much to do with Tailmon but it was the way I installed Tailscale on the router.