Did you make sure under wireguard - local the port you are redirecting to is what wireguard is running on.
That would make it much harder. To test you would need to change the port to something else in your rule without changing anything else and confirm it works and then if this is the case consider another port to use that might bypass. The best is 53 and 443 but if those are out the question you might have success with port 465 as many firewalls allow this port (secure mail for gmail for example).
Why not just have WG listen on 465 and forget about port forwarding?