Not Wireguard fault, but in my case IPSEC worked better. I guess I could encapsulate it, but it's just annoying to do and on some platforms it's just too much trouble.
If your firewall blocks UDP packets in general, you're in a world of pain either way, since TCP over TCP is pretty bad.
[0] https://www.wireguard.com/quickstart/#nat-and-firewall-trave...
by @mistaken, not Linus: http://lists.openwall.net/netdev/2018/08/02/124
OpenVPN is a mess. IPSEC and basically all implementations thereof are messes.
(As a personal anecdote, have you ever tried to get OpenVPN to do anything remotely sensible with MTUs or MTU-related ICMP errors? You can’t, because every possible configuration gets it at least partially wrong [0]. Wireguard get it entirely correct AFAICT.)