Confirmed, responder NOT set. (I then also set responder, applied, then again unset responder, applied. No change).
FQDN
yeah, yeah, brain fart on my part, sorry; I'm getting over the flu - brain may not be working so well at the moment... (I was around at Carnegie-Mellon University in the 1980s when DNS happened. I actually met Cricket Liu at one point when I was in the security group at Delta Air Lines in the late 1990s. [Insert other fascinating name-drops here]. Back then this tech stuff was easier for me).
FYI, my ip firewall filter contains NO action=drop rules, as this device is never meant to be broadly exposed to the Internet. There is no IPsec configured. Only the two simple NAT/masq rules as mentioned above. There just shouldn't be anything in this configuration which should be able to cause a WireGuard peer handshake initiation packet to be vanished without a trace like this.
Restarting - have already done, several times.
The one thing that I haven't done (7.24 bug) is completely delete ALL WireGuard configuration and re-create it; what I did do was to delete the wg1 interface and the MikroTik4 peer, but I left two road warrier 'client' peers of this router in the WireGuard peers configuration.
I'll clear away the entire WireGuard configuration, reboot, and re-create it:
No, that made no difference either.
So, supout -> MikroTik support, referencing this forum thread, with the brief summary "Even after extensive community discussion and testing a variety of things, it looks like something broke, possibly with the 7.24 upgrade persistent even downgrading to 7.23.3 (still firmware 7.24) which completely turns off WireGuard's ability/willingness to initiate a connection to a peer" ?
(I've never used netinstall; separately, I use ACME certificates with functionality that was added from 7.23, so going back to the LTS 7.21 tree would definitely result in some configuration breakage; and it worked on 7.23, so if I have to do this, I'd try with 7.23 first).
I do have a full BKP (as well as an EXP) of the 7.23.last configuration from just before all of this occurred. I think that might be the least-impactful place to start.... ? But I'd like to give MikroTik support the opportunity to debug, first.
So, anything else/ any other way to state, the problem in the support ticket that I'll raise?
thank you, all!