Is there a way to get a letsencrypt certificate for the factory DDNS on the MT6000?

We'll look again at DNS, but this does not explain why it was working with Dockerized WG vs Flint2 WG app not working. I was investigating this thread here Router as Wireguard client blocks LAN reachability to same Wireguard server the router is connected to - #18 by hansome

https://forum.gl-inet.com/t/endpoint-wireguard-vpn-over-wireguard-router-client-vpn/37153/14

Many times in other posts you point to DNS issues and not WG or router settings.

I saw this post;

And on the wireguard client side, remove the route to the wireguard server public IP.

ip route del  1.2.3.4

It needs to be firmware 4.2.3 and above.

This way the traffic will go via VPN tunnel otherwise it will go via WAN interface which is not allowed by default.