This issue will need to be updated with some further info and is opened to track my evidence in this issue to report it upstream.
With direct routing and kube proxy replacement enabled on Cilium certain devices cannot connect over a wireguard tunnel managed externally from cilium. MTU is set to really low levels to make it work on some devices (1280). Along with adjusting mss
In order to avoid this "oddness" I've temporarily disabled both until I have more time to investigate and deployed kube-proxy.