I am configuring Wireguard a wan network that has both LAN usage hosts and WAN hosts. Let's call the LAN hosts A and B, and let's call C the host connected by WAN. I
Wireguard network IPs
OpenWRT router 10.0.0.1
A 10.0.0.2
B 10.0.0.3
C 10.0.0.4
I successfully managed to let A and B ping the OpenWRT router Wireguard IP, but the WAN host C, it cannot ping it. I also tried to move wg0 interface from unspecified firewall zone to LAN, but it did not fix the problem. Can you help me? I don't post the client configuration since I know that is okay because I am a longtime Wireguard user on "regular" Linux machines, but I am not yet so practice with OpenWRT configuration. Thank you
/etc/config/network
config interface 'loopback'
option ifname 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'removed_be_me::/48'
config interface 'lan'
option type 'bridge'
option ifname 'lan0 lan1 lan2 lan3 lan4'
option proto 'static'
option ipaddr '192.168.1.1'
option netmask '255.255.255.0'
option ip6assign '60'
option _turris_mode 'managed'
config interface 'wan'
option ifname 'eth2'
option proto 'dhcp'
option ipv6 '0'
option hostname 'xxxxxx'
config interface 'wan6'
option ifname '@wan'
option proto 'none'
config interface 'wg0'
option proto 'wireguard'
option private_key **REMOVED**
option listen_port '51000'
list addresses '10.0.0.1/24'
config wireguard_wg0
option public_key **REMOVED**
option description 'A'
option endpoint_port '51000'
option endpoint_host '192.168.1.20'
list allowed_ips '10.0.0.2/32'
config wireguard_wg0
option endpoint_port '51000'
option public_key **REMOVED**
option description 'B'
option endpoint_host '192.168.1.30'
list allowed_ips '10.0.0.3/32'
config wireguard_wg0
option public_key **removed_be_me**
option description 'host from WAN'
list allowed_ips '10.0.0.4/32'
/etc/config/firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option network 'lan wg0'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan wan6'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config rule 'turris_wan_6in4_rule'
option enabled '0'