Put Brume behind the FW, and let it be the WG end-point
Fix it’s IP to a static IP inside your LAN, and port forward just the WG ports.
Don’t need to do port forwards other that WG on the edge router