First, this is a NAT configuration; not a routed configuration.
Computers on the LAN will not be able to initiate sessions with computers on the ZeroTier network.
Second, you’ve set my.zerotier.com to assign LAN addresses to ZeroTier clients, which is backwards unless you’re using network jargon incorrectly, which would be another mistake.
Third, you should describe what 192.168.88.196 is doing. Both sides are RFC1918 ranges, so you should clarify what you mean by “physical address”.
Fourth, directly using iptables is difficult. Use a network configuration tool provided by distro or by the desktop environment instead.