Wireguard tunnel between pfsense - unifi

Hello

I’ve working joining two sites via wireguard tunnel. We just need to pass some registers and voip for the moment. We are using wireguard since it was easier to configure and one of the sites is behing CG-Nat. The new site just has 2 phones and one ac reader so the traffic is low and needs to go the main site.

On the main site we have a pfsense and a public ip which we can connect. I checked this video https://www.youtube.com/watch?v=WXkWP-JZOd8 to configure the pfsense side and downloaded the config file.
On the new site we have a UCG-Ultra and its behind CG-Nat. I uploaded the config file on the wireguard client config inside Unifi Network. The file validated correctly and the tunnel got established.
I’ve checked on the pfsense and the UCG both show connected. I had to create a firewall rule on the UCG so it could answer the monitor ping from the pfsense. The voip vlan on the new site is fully routed via the tunnel, but the phone doesn’t register on the pbx also when I try to access the web interface of the phones from the main site they don’t answer. I did a packet capture on the tunnel and some DNS queries came from the phones and got answered by our DNS service on the main site.

We have zone firewall enabled but seems the trafic isn’t passing. Does someone has experience with this setup. I think I’m missing some firewall rules or the UCG is blocking the traffic by default since it’s coming from an external zone.

Wouldn’t the traffic be coming in from the VPN zone since you are on a WG VPN? Do you have a pass rule from the VPN to the location of the PBX?