This looks good but are you sure you need both udp and tcp? This doesn’t matter much for your issue though.
It is required because the default rules are to block all incoming traffic on all interfaces, this also applies to “new” interfaces created by VPN and not just eth0 and vifX.Y interfaces managed by Qubes OS.
When trying to connect, are you doing it from the remote VPN peer or the public IP address? You need to setup a port redirection on the VPN server to redirect traffic from the public IP address / port to the qube on its VPN IP.
VPN providers do not offer port forwarding in most cases, and when they do like Proton VPN, they only redirect a single random port using a slightly complicated method.
Yes, you just need to open the port locally.
Could you share a bit more information, in private if needed?
Yes, I’ve also been trying for a very long time to set up my Mullvad WireGuard on Fedora 44 Xfce. However, I haven’t been able to do it yet. I don’t know where I’m going wrong either.
It surprises me that there isn’t any ready-made software out there that you just have to install and then enter a few settings into.
If something like that doesn’t exist, a photo tutorial would be exactly what I need—a step-by-step guide specifically for newbies using Qubes for the first time.
You know that Mullvad provide packages for Fedora to install their tool?
If that seems complicated, I have a single package to install in dom0 to
create a Mullvad template based on Debian minimal template, and a
sys-mullvad qube.
You can get that from https://qubes.3isec.org/tasks.html
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.