If you only want to allow WireGuard, you only need to forward 51820 UDP. Although some manuals recommend using both UDP and TCP.