I don’t see a need for NAT, but I suggest removing iptables
completely for now. Delete the route you created.
Make sure forwarding is enabled on RPi.
Create the proper managed route on the controller, then check routing table on RPi and other ZT endpoints. Modify the table on the default router in your LAN by adding a static route to ZT subnet via RPi address (if necessary).
See this for the hint about routes: Zerotier router setup not working - #4 by AndrewZ