[–] 13 points 2 years ago (2 children)

Put your external facing services behind the VPN, or at least put them in a separate VLAN that's firewalled in such a way that they can't reach the rest of the network if they become compromised.

  • source
  • [–] 5 points 2 years ago* (last edited 2 years ago) (1 child)

    I would advise that you instead also connect the Windows machine to the VPS with WireGuard as 10.1.0.3, basically mirroring what you've done on the Ubuntu server. The routing will be a mess otherwise. Another option is running the WireGuard tunnel on your gateway with something like OPNsense.

  • source
  • parent
  • context
  • [–] 2 points 2 years ago (3 children)

    Does the machine running the WireGuard tunnel to the VPS acts as a "router" aka gateway for the network? Otherwise the windows machine doesn't have a return path for the connection.

  • source
  • [–] 1 point 2 years ago*

    S920

    I'm running this as my router. It handles a 500/500mbit connection over WireGuard for me without a problem. CPU usage can spike up to 80% when I push it as much as I can, so depending on how it scales I'm not 100% sure how it would handle 1gbit routing+vpn for example.

  • source
  • parent
  • context
  • view more: next ›