Site to site wireguard internet issue

Hi everyone,
I have been trying to for this for a day now. Pulling my hair out. You wouldn’t know I had my ccna at one time.
I have two hAP x³. One is behind nat and the other is directly on the internet.
I have been able to get wireguard interfaces/tunnel created. I have created two ip addresses on each side on these two interfaces (10.255.255.1 on client and .2 on server /30) . I can ping across the tunnel to these addresses from each hAP.
I have made a static route on the client to reach the server xx.xx.xx.232 via 10.0.0.1 (a route for the tunnel through the internet)
And another static default route for all other traffic 0.0.0.0/0 via [wireguard1] [10.255.255.1] [10.255.255.2] <<things I’ve tried are in [.].

A laptop connected to client hAP by wifi can ping 10.255.255.1, but not 2, or 8.8.8.8. The client hAP itself can ping anything, including 8.8.8.8 just fine.
I’m not seeing firewall counters blocking packets.


Any help appreciated
hap3client.txt (7.96 KB)

Check allowed addresses on peer settings of other Hap, the one where the config is not shown.