ICMP is not TCP/UDP and ICMP is not Port-Based.
So, if your router hasn't a ICMP forward option, you can only try something like Exposed Host (sometimes (wrongly) named DMZ)
But why you want to do that? Normally it's more practicable to set the vpn-server listen on tcp/443 (https),
because https is often allowed (also in very restricted networks)