Wireguard RemoteAccess and FW Rule - defconf: drop all not coming from LAN

Hi
I’m completly new to RouterOS.
setup is following:
local ip network 192.168.10.X
WAN Static IP 10.10.100.15 NAT from Internet provider.
there is port forwarding from public Internet IP adress.
I can connect to Wireguard, ping works etc.
but when I’m trying to login to Mikrotik it’s not allowing unless I disable following rule: defconf: drop all not coming from LAN
so the question is it now a safe setup with this rule disabled or I should change something in that rule ?

https://forum.mikrotik.com/viewtopic.php?t=180838