> So you recommend manually specifying an entry guard, instead of letting
> Tor choose? Why?

Not at all.
Let your network gateway (or each PC) forward all outgoing traffic (or only 
traffic to Tor node, with iptables + ipset) through your VPN. And use the 
normal way a normal Tor client per PC, configuring all your application to use 
the standard (and local this time) SOCKS5 proxy or do transparent proxying to 
(local) Trans/DNSPort.

