I am currently setting up Wireguard side to side with ipv6. I already have a site-to-site configuration based on ipv4. Side A is my home network with an Openwrt router (Dynalink DL-WRX36) on the other side is an OPNsense firewall/router virtualized on proxmox in a datacenter, behind it are some servers like adguardhome and samba. On both sides at least the assignment of IPv6 addresses works. From the Openwrt router and directly from the OPNsense I can ping the peers.
From the Windows and Linux client in the LAN I cannot reach the IPv6 addresses. How do I have to proceed ? What is different in the routing of the IPv6 addresses?
Make sure the wireguard interfaces have link-local IPs. OpenWrt does not install them by default. IPv6 really does not work well without them, as it is technically the gateway to the LANs on a router. This means that the other side's link-local needs to be an allowed IP.
If your network is not only site to site but also point to point (the only peer on both wireguard interfaces is the other site) then you can simplify things by setting allowed ips to ::/0 on both ends and don't route allowed ips. Control the routing outside of Wireguard.