@ngtimofeev
In your case, I would add some details, would close access to VPN clients to the internal network for ZONE wareguard> WAN Input > Drop, so they can’t reach the web interface of the mango router at IP 10.0.0.1 and I would create another traffic rules that allow only IP address of your personal VPN client for Mango(e.g. with an IP 10.0.0.2/32, see my e.g below), to access to the mango shell, brume shell and other ip addresses from internal network, if required. Very important ! It must be dragged and droped above the deny rule in your case “forbid-wg-to-lan” then saved and applied.