I can ping from the opnsense (site "A") the host on the site "B". But I can't from hosts of "A" ping those on "B". Neither from the openwrt (site "B") or its host to "A".
Opnsense "A" pings hosts on "B"
Hosts on "A" don't ping Openwrt "B"
Hosts on "A" don't ping hosts on "B"
Openwrt "B" don't ping Opnsense "A"
Openwrt "B" don't ping Hosts on "A".
# uci show network.wgclient; wg show; ip route show
network.wgclient=wireguard_WGPSA
network.wgclient.description='WGPSA'
network.wgclient.route_allowed_ips='1'
network.wgclient.endpoint_host='REMOTE_WAN_SITE_A_PUBLIC_IP'
network.wgclient.endpoint_port='63588'
network.wgclient.persistent_keepalive='25'
network.wgclient.public_key='*****************************'
network.wgclient.allowed_ips='192.168.10.1/24' '192.168.11.1/24' '10.0.0.1/32' '192.168.10.1/24'
interface: WGPSA
public key: ******************************
private key: (hidden)
listening port: 63588
peer: **********************************
endpoint: REMOTE_WAN_SITE_A_PUBLIC_IP:63588
allowed ips: 192.168.11.0/24, 10.0.0.1/32, 192.168.10.0/24
transfer: 0 B received, 1.01 KiB sent
persistent keepalive: every 25 seconds
default via 192.168.1.254 dev eth0.2 src 192.168.1.100
10.0.0.0/24 dev WGPSA scope link src 10.0.0.2
10.0.0.1 dev WGPSA scope link
REMOTE_WAN_SITE_A_PUBLIC_IP via 192.168.1.254 dev eth0.2
192.168.0.0/24 dev br-lan scope link src 192.168.0.1
192.168.1.0/24 dev eth0.2 scope link src 192.168.1.100
192.168.20.0/24 via 192.168.0.12 dev br-lan
I'm sure it is on the Openwrt Site "B" ("origin"):
# ip route show table all
default via 192.168.1.254 dev eth0.2 src 192.168.1.100
10.0.0.0/24 dev WGPSA scope link src 10.0.0.2
10.0.0.1 dev WGPSA scope link
******************* via 192.168.1.254 dev eth0.2
192.168.0.0/24 dev br-lan scope link src 192.168.0.1
192.168.1.0/24 dev eth0.2 scope link src 192.168.1.100
192.168.10.0/24 dev WGPSA scope link
192.168.11.0/24 dev WGPSA scope link
192.168.20.0/24 dev WGPSA scope link
213.13.24.0/24 dev WGPSA scope link
broadcast 10.0.0.0 dev WGPSA table local scope link src 10.0.0.2
local 10.0.0.2 dev WGPSA table local scope host src 10.0.0.2
broadcast 10.0.0.255 dev WGPSA table local scope link src 10.0.0.2
broadcast 127.0.0.0 dev lo table local scope link src 127.0.0.1
local 127.0.0.0/8 dev lo table local scope host src 127.0.0.1
local 127.0.0.1 dev lo table local scope host src 127.0.0.1
broadcast 127.255.255.255 dev lo table local scope link src 127.0.0.1
broadcast 192.168.0.0 dev br-lan table local scope link src 192.168.0.1
local 192.168.0.1 dev br-lan table local scope host src 192.168.0.1
broadcast 192.168.0.255 dev br-lan table local scope link src 192.168.0.1
broadcast 192.168.1.0 dev eth0.2 table local scope link src 192.168.1.100
local 192.168.1.100 dev eth0.2 table local scope host src 192.168.1.100
broadcast 192.168.1.255 dev eth0.2 table local scope link src 192.168.1.100
unreachable fd25:9b6f:f04b::/48 dev lo metric 2147483647
fe80::/64 dev eth1 metric 256
fe80::/64 dev eth0 metric 256
fe80::/64 dev eth0.2 metric 256
fe80::/64 dev br-lan metric 256
fe80::/64 dev wlan0 metric 256
fe80::/64 dev wlan1 metric 256
local ::1 dev lo table local metric 0
anycast fe80:: dev eth1 table local metric 0
anycast fe80:: dev eth0.2 table local metric 0
anycast fe80:: dev eth0 table local metric 0
anycast fe80:: dev br-lan table local metric 0
anycast fe80:: dev wlan0 table local metric 0
anycast fe80:: dev wlan1 table local metric 0
local fe80::1691:82ff:fe7e:3254 dev eth0.2 table local metric 0
local fe80::1691:82ff:fe7e:3254 dev br-lan table local metric 0
local fe80::1691:82ff:fe83:c99 dev wlan0 table local metric 0
local fe80::1691:82ff:fe83:c9a dev wlan1 table local metric 0
local fe80::345c:4aff:fe1e:b84c dev eth1 table local metric 0
local fe80::3c3e:bdff:fec1:cada dev eth0 table local metric 0
multicast ff00::/8 dev eth1 table local metric 256
multicast ff00::/8 dev eth0 table local metric 256
multicast ff00::/8 dev eth0.2 table local metric 256
multicast ff00::/8 dev br-lan table local metric 256
multicast ff00::/8 dev wlan0 table local metric 256
multicast ff00::/8 dev wlan1 table local metric 256
multicast ff00::/8 dev WGPSA table local metric 256
# uci show network.wgclient.allowed_ips
network.wgclient.allowed_ips='10.0.0.1/32' '192.168.10.0/24' '192.168.11.0/24' '192.168.20.0/24' '213.13.24.0/24'