Secure WireGuard Remote Access System
Budget: €8 – €30 EUR
Hi
I would like to explain my current setup and what I want to achieve regarding **remote access using WireGuard**.
---
### 1. Current Situation
I have:
* A **central server (VPS or main router)** running **WireGuard**
* A **MikroTik router** at the site
* Multiple **Ubiquiti and Mimosa devices** (sectors, CPEs, PtP links)
These devices are **connected behind the MikroTik** (same LAN or VLANs)
---
### 2. Goal
My goal is to use **WireGuard as a secure remote access tunnel** that allows me to:
* Access the **MikroTik router** remotely (Winbox, SSH, WebFig)
* Access **Ubiquiti & Mimosa devices** behind the MikroTik
* Do all management **without exposing public IPs** or opening multiple ports
---
### 3. Desired Architecture
* The **WireGuard server** acts as a central hub
* MikroTik connects to it as a **WireGuard client**
* Remote users (laptop / phone) also connect as WireGuard peers
* Routing is configured so that:
* Remote users can reach the MikroTik LAN
* Remote users can reach Ubiquiti & Mimosa management IPs
* No NAT inside the tunnel if possible (pure routing preferred)
---
### 4. Access Requirements
* Ability to:
* Open Winbox directly via WireGuard IP
* Access Ubiquiti & Mimosa web interfaces
* SSH / HTTPS access where needed
* Stable routing (no random disconnects)
* Simple IP plan (e.g. 10.0.0.0/24 or similar)
---
### 5. Security & Best Practices
* Only WireGuard access (no public management ports)
* Firewall rules to:
* Allow management traffic via WireGuard only
* Restrict unnecessary access
* Easy way to add/remove peers later
---
### 6. Optional / Future Enhancements
* Separate WireGuard profiles (Admin / Technician)
* Monitoring access (who connects and when)
* Integration later with monitoring systems (Zabbix, etc.)
---
### 7. What I Need From You
Please advise on:
* Best routing approach (static routes vs policy routing)
* Recommended IP addressing scheme
* Firewall & security best practices
* Any improvements to ensure long-term stability
Best regards,
Shaif
I would like to explain my current setup and what I want to achieve regarding **remote access using WireGuard**.
---
### 1. Current Situation
I have:
* A **central server (VPS or main router)** running **WireGuard**
* A **MikroTik router** at the site
* Multiple **Ubiquiti and Mimosa devices** (sectors, CPEs, PtP links)
These devices are **connected behind the MikroTik** (same LAN or VLANs)
---
### 2. Goal
My goal is to use **WireGuard as a secure remote access tunnel** that allows me to:
* Access the **MikroTik router** remotely (Winbox, SSH, WebFig)
* Access **Ubiquiti & Mimosa devices** behind the MikroTik
* Do all management **without exposing public IPs** or opening multiple ports
---
### 3. Desired Architecture
* The **WireGuard server** acts as a central hub
* MikroTik connects to it as a **WireGuard client**
* Remote users (laptop / phone) also connect as WireGuard peers
* Routing is configured so that:
* Remote users can reach the MikroTik LAN
* Remote users can reach Ubiquiti & Mimosa management IPs
* No NAT inside the tunnel if possible (pure routing preferred)
---
### 4. Access Requirements
* Ability to:
* Open Winbox directly via WireGuard IP
* Access Ubiquiti & Mimosa web interfaces
* SSH / HTTPS access where needed
* Stable routing (no random disconnects)
* Simple IP plan (e.g. 10.0.0.0/24 or similar)
---
### 5. Security & Best Practices
* Only WireGuard access (no public management ports)
* Firewall rules to:
* Allow management traffic via WireGuard only
* Restrict unnecessary access
* Easy way to add/remove peers later
---
### 6. Optional / Future Enhancements
* Separate WireGuard profiles (Admin / Technician)
* Monitoring access (who connects and when)
* Integration later with monitoring systems (Zabbix, etc.)
---
### 7. What I Need From You
Please advise on:
* Best routing approach (static routes vs policy routing)
* Recommended IP addressing scheme
* Firewall & security best practices
* Any improvements to ensure long-term stability
Best regards,
Shaif
Related categories:
System Admin
Linux
Cisco
Network Administration
Network Security
VPN
Ubiquiti
Network Monitoring