if I create an wg interface - I don't have to create NAT Port forwarding
and I dont have to config IPc4 in interface settings.
Now I receive may DNS and ICMP blocks.
wg1 2022-10-21T11:08:53 192.168.20.21:33888 192.168.20.1:53 udp Default deny / state violation rule wg1 2022-10-21T11:08:53 192.168.20.21:64906 192.168.20.1:53 udp Default deny / state violation rule wg1 2022-10-21T11:08:53 192.168.20.21:6700 192.168.20.1:53 udp Default deny / state violation rule wg1 2022-10-21T11:08:42 192.168.20.21:12967 192.168.20.1:53 udp Default deny / state violation rule wg1 2022-10-21T11:08:33 192.168.20.21:45439 192.168.20.1:53 udp Default deny / state violation rule
To do this I have to deactivate also DHCP on this interface.
Update - I have to create the any rule in Interface - WireGuard (Group) then FW and DNS is allowed. This interface has been created automatically with the installation of WG.
Traceroute to 8.8.8.8 - only one HOP - 192.168.20.1