Howdy
Found it…
Basically PPPoE setup corrupted LUCI in 3.215 (I know: shouldn’t be using snapshot…) - went back to 3.212
anyway - went back to ISP router and DMZ’ed main site… then LUCI setup to allow all traffic is as following:

  1. add two unmanaged interfaces on WG0 and WG1
  2. Add WG0 to wireguard zone
  3. Create new sitetosite zone with wg1
  4. Disable masquarade on wireguard zone
  5. allow forward between LAN, wireguard and site to site

1 Like