Help with setting up wireguard site to site to firewalla

I have a GLiNet A1300 trying to use as a travel VPN router/hotspot. I am able to connect normally to a captive hotspot with the A1300 and log in and surf the internet.

Now I am trying to enable a site to site VPN to my home. My home has a firewalla gold with built in wireguard and open VPN protocols. My understanding is that I enable the firewalla VPN first (started with wireguard). Then I download the conf file and transfer it to the A1300 to a new profile. Then I start up the VPN client on the A1300. Everything shows it works so far, the A1300 says it connects, myt firewalla shows that a client is connected. What fails is that I am unable now to connect to the internet with the laptop connected to the A1300. What worked before VPN is turned on doesnt work. I attach the log from the A1300:“Tue Sep 26 16:29:31 2023 daemon.notice netifd: Interface ‘wgclient’ is setting up now\nTue Sep 26 16:29:32 2023 daemon.notice netifd: wgclient (1196): Error: inet6 prefix is expected rather than "".\nTue Sep 26 16:29:37 2023 kern.info kernel: [ 1994.163905] wireguard: wireguard-hotplug IFNAME=wgclient ACTION=REKEY-TIMEOUT\nTue Sep 26 16:29:37 2023 daemon.notice netifd: wgclient (1734): RTNETLINK answers: No such process\nTue Sep 26 16:29:37 2023 daemon.notice netifd: Interface ‘wgclient’ is now down\nTue Sep 26 16:29:38 2023 user.notice mwan3[1888]: Execute ifdown event on interface wgclient (unknown)\nTue Sep 26 16:29:39 2023 user.notice firewall: Reloading firewall due to ifdown of wgclient ()\nTue Sep 26 16:30:41 2023 daemon.notice netifd: Interface ‘wgclient’ is setting up now\nTue Sep 26 16:30:41 2023 daemon.notice netifd: wgclient (4711): Error: inet6 prefix is expected rather than "".\nTue Sep 26 16:30:41 2023 kern.info kernel: [ 2058.341923] wireguard: wireguard-hotplug IFNAME=wgclient ACTION=KEYPAIR-CREATED\nTue Sep 26 16:30:42 2023 daemon.notice netifd: Network device ‘wgclient’ link is up\nTue Sep 26 16:30:42 2023 daemon.notice netifd: Interface ‘wgclient’ is now up\nTue Sep 26 16:30:43 2023 user.notice mwan3[5023]: Execute ifup event on interface wgclient (wgclient)\nTue Sep 26 16:30:43 2023 user.notice wgclient-up: env value:T_J_V_ifname=string J_V_address_external=1 USER=root ifname=wgclient ACTION=KEYPAIR-CREATED N_J_V_address_external=address-external SHLVL=2 J_V_keep=1 HOME=/ HOTPLUG_TYPE=wireguard T_J_V_interface=string J_V_ifname=wgclient T_J_V_link_up=boolean LOGNAME=root DEVICENAME= T_J_V_action=int TERM=linux SUBSYSTEM=wireguard PATH=/usr/sbin:/usr/bin:/sbin:/bin CONFIG_LIST_STATE= J_V_interface=wgclient K_J_V= action ifname link_up address_external keep interface J_V_link_up=1 J_V_action=0 T_J_V_address_external=boolean N_J_V_link_up=link-up T_J_V_keep=boolean PWD=/ JSON_CUR=J_V CONFIG_SECTIONS=global AzireVPN Mullvad FromApp group_9477 group_8796 group_1762 group_1315 peer_2001 CONFIG_cfg030f15_ports=\nTue Sep 26 16:30:43 2023 user.notice mwan3[5023]: Starting tracker on interface wgclient (wgclient)\nTue Sep 26 16:30:47 2023 user.notice firewall: Reloading firewall due to ifup of wgclient (wgclient)\n”

I then try openvpn and I cannot connect due to the error in the log:
Tue Sep 26 16:28:03 2023 daemon.notice ovpnclient[29110]: library versions: OpenSSL 1.1.1m 14 Dec 2021, LZO 2.10\nTue Sep 26 16:28:03 2023 daemon.warn ovpnclient[29110]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts\nTue Sep 26 16:28:03 2023 daemon.err ovpnclient[29110]: neither stdin nor stderr are a tty device and you have neither a controlling tty nor systemd - can’t ask for ‘Enter Private Key Password:’. If you used --daemon, you need to use --askpass to make passphrase-protected keys work, and you can not use --auth-nocache.\nTue Sep 26 16:28:03 2023 daemon.notice ovpnclient[29110]: Exiting due to fatal error\nTue Sep 26 16:28:03 2023 daemon.notice netifd: ovpnclient (29117): cat: can’t open ‘/tmp/run/ovpn_resolved_ip’: No such file or directory\n"

any help would be appreciated!

For openvpn, pls edit your opvn file and add one line,

askpass

Then upload to the router. The router should ask you to input private key passphrase

Cannot see anything of wireguard.