Local Blynk server accessible from the Internet: How to secure?

nope…it is the other way around.
Destination is the destination network (192.168.168.0/24) and via is the zt-ip of the PC running the zt-client…you find it on the same page, further down in the members section…managed IPs column.

Remember, in zt-central you are confuguirung the zt-network.
Destination routes point/are outside of that network and gateways (via) are the devices (zt-IIP) that act as gateway.
This declares traffic from zt to outside.

In order to have a bi-directional connection, outside networks need a route into zt.
like destination: 10.11.12.0/24 and gateway(via) the local ip oif the host running zt-client (192.168.168.1) …this need to be applied in the local router, managing 192.168.168.0/24

Edit: this is how it looks on my zt-central routing page:

Obviusly I am connecting two sites via zt, one with multiple networks, like 192.168.[0|10|20|30|40].0/24 via 10.x.x.25 and one with 192.168.8.0/24 via 10.x.x.254