I'd like to put a bridging router between LAN and GW to "divert" traffic (intended for the gatway) from the bridge and route it to a vpn-interface on the same router.
Normally it should not be bridging but routing.
You could change the default gateway of the lan hosts that need to use the wireguard.
Or you can try if there is some way to do DNAT in ebtables.
I'v done some routing setups an they all work very well, but in this case the router should not modify the existing lan (dhcp, portforwarding, static routing from gateway to lan should not be modified)
Good idea!
Forgot to mention that the wireguard interface on the router is the client and nat is done by the other side so it will be double-nat
But i'll try this tomorrow.