Secure WireGuard Remote Access System

Job ID: 40171032

Budget: €8 – €30 EUR

Hi

I would like to explain my current setup and what I want to achieve regarding **remote access using WireGuard**.

---

### 1. Current Situation

I have:

* A **central server (VPS or main router)** running **WireGuard**
* A **MikroTik router** at the site
* Multiple **Ubiquiti and Mimosa devices** (sectors, CPEs, PtP links)
These devices are **connected behind the MikroTik** (same LAN or VLANs)

---

### 2. Goal

My goal is to use **WireGuard as a secure remote access tunnel** that allows me to:

* Access the **MikroTik router** remotely (Winbox, SSH, WebFig)
* Access **Ubiquiti & Mimosa devices** behind the MikroTik
* Do all management **without exposing public IPs** or opening multiple ports

---

### 3. Desired Architecture

* The **WireGuard server** acts as a central hub
* MikroTik connects to it as a **WireGuard client**
* Remote users (laptop / phone) also connect as WireGuard peers
* Routing is configured so that:

* Remote users can reach the MikroTik LAN
* Remote users can reach Ubiquiti & Mimosa management IPs
* No NAT inside the tunnel if possible (pure routing preferred)

---

### 4. Access Requirements

* Ability to:

* Open Winbox directly via WireGuard IP
* Access Ubiquiti & Mimosa web interfaces
* SSH / HTTPS access where needed
* Stable routing (no random disconnects)
* Simple IP plan (e.g. 10.0.0.0/24 or similar)

---

### 5. Security & Best Practices

* Only WireGuard access (no public management ports)
* Firewall rules to:

* Allow management traffic via WireGuard only
* Restrict unnecessary access
* Easy way to add/remove peers later

---

### 6. Optional / Future Enhancements

* Separate WireGuard profiles (Admin / Technician)
* Monitoring access (who connects and when)
* Integration later with monitoring systems (Zabbix, etc.)

---

### 7. What I Need From You

Please advise on:

* Best routing approach (static routes vs policy routing)
* Recommended IP addressing scheme
* Firewall & security best practices
* Any improvements to ensure long-term stability

Best regards,
Shaif