Thanks @kyson-lok.

Can I setup Wireguard server on my remote router, and login as client from my home PC or Android? I’ve tried to do this but cannot get connections to the Slate VPN from PC or Android. Android Wireguard claims a connection, but GL admin panel doesn’t show any corresponding client. PC’s TunSafe client shows handshake is continually retrying, even if all firewalls are turned off.

Wireshark shows the traffic on source udp.port == 51820, heading for the correct IP address from the .conf file. However, there’s no return traffic except an ICMP redirect, redirect for host.

I additionally tried setting up a WiFi hotspot with my phone for the PC. This eliminated the ICMP redirects which were coming from my home router, but did not achieve any other result.

Finally, I monitored the WiFi link to the GL router, and found the UDP handshake arriving, but the response from the router’s IP was ICMP, Destination Unreachable, Port Unreachable.

I need to monitor the issue from within LuCi, from the system logs. How should I do this?

And do I need to open a port on the firewall of the Slate or of the PC, for the VPN traffic?
I found the inbound rule in LuCi for Wireguard (WAN to device at port 51820).

Thirdly, should I quit using Wireguard and concentrate upon OpenVPN instead?