IPv6 forwarding from Internet to WireGuard peers?

Server:

firewall-cmd --policy vpnbackward --add-rich-rule 'rule family="ipv6" masquerade'

Masquerading IPs from Internet as the server will make it work, despite there is no sensible reason to.
I saw a high rx_frame_errors in /sys/class/net/wg/statistics/.
Better advice is welcome, I don’t like seeing masquerade in IPv6…