so to access grafana over the vpn try using the ip of the virtual IF.

if this doesn't work use this command to NAT the address
sudo iptables -t nat -A PREROUTING -d -p tcp --dport 4000 -j DNAT --to-destination

Then connect again to and the firewall will NAT the address to the eth0 interface and it should work