making the wireguard node an egress, allows forwarding from any node (10.70.0.0/20) to the metallb ip range (10.71.0.0/24). but, for some reason, once the packet reaches the egress node, it doesnt seem to make the final hop to the k3s-node where the kubernetes service is actually running.