@Bob-Dig
No. I can ping out though on a shell on my netgate (freebsd uses ICMP for pings unlike cisco routers which are udp)
and can specify no fragment with up to 1472:
ping -D -t 1 -s 1472 10.2.0.1
PING 10.2.0.1 (10.2.0.1): 1472 data bytes
1480 bytes from 10.2.0.1: icmp_seq=0 ttl=64 time=148.918 ms
--- 10.2.0.1 ping statistics ---
1 packets transmitted, 1 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 148.918/148.918/148.918/0.000 ms
Where then trying at 1473 I get ping: sendto: Message too long
The pings that do work, now show up in packet captures on that WG interface.
So pretty sure MTU/MSS cant be the problem
Whats really bizarre though is if I set my squids outgoing interface back to the cyberghost one, then squid clients going to ipinfo show an italian IP address as expected. But then if I set squids outgoing interface to the new WG tunnel interface then squid clients that use ipinfo return the local ISP WAN IP address.