  1. Now things got a bit funny. While waiting for your answers I tried to remove parts of these chains to see what is necessary for my setup to work.After deleting ; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE my clients could not connect to each other while still being able to connect to server.After that I tried to restore previous setting and no matter what I did I was not able to return to my previously working setup. Then I flushed iptables, reenabled ufw and... locked myself out of ssh :) Then I had to reinstall my VPS and start from scratch. Just enabling net.ipv4.ip_forward is not enough for the clients to be able to connect to each other. Only adding full chains from first post to [Interface] section of servers wg0.conf enables that. Which I don't understand since all traffic should go through wg0...

