@feld I've never tried doing that with Wireguard, so I can't really help more than this. The last remaining piece of information I have is that wg-quick does some shenanigans with routes and maybe that broke it/prevents it from working even though it shouldn't. For example if you specify AllowedIPs on peer to 0.0.0.0, ::0, it makes that the default route for everything. Which is something you probably already know.