@larieu Not sure if I understand the idea behind it:
I am using VPN currently. If I grant VPN access to the user, the zonebridge, which must connect to the samba share would need to open the VPN-tunnel first, which is not possible as this box is not an interfaced computer (keyboard, shell...) but a piece of home entertainment equipment with a corresponding piece of software to configure it remotely. Unfortunately there is no way to add/use VPN features on it.
Do you possibly suggest to connect the Sonos box to a Computer on the WAN Side, which tunnels through to SME using VPN, so, that samba can be used? If so, I think it could be possible but only as a last resort, as it would mean that I have another computer up and running all time only for the purpose of accessing my music.
@johnp: Interesting idea. It could actually work. If I get you right, the Router-AP were local and part of my local network. The LAN currently is running on 10.0.0.x. I'd have to change that to 192.168.0.x, as my router is fixed on this IP-range. It is not even easy to test it.
I have uploaded a picture of my understanding of the different networks as discussd here:

Is this, what you suggested?