Is this a valid wireguard server? The endpoint_host IP is private.
You are tunneling all traffic to that wg server, so if it isn't meant to connect you to the internet, you are blackholing yourself.
192.168.122.194 is a valid local wireguard server.
my wan interface is "eth1". Without wireguard sections, I'm able to do "ping -I eth1 8.8.8.8". And when I add add wireguard sections, "ping -I eth1 8.8.8.8" fails.
Then it's not strange it doesn't know where to send it.
If you really need to ping google dns from eth1 when wg is up, add a static route for it via eth1.