Site to Site VPN For Family Home

Hey Everyone,

Wanting to put a small NUC at my in laws so I can put pihole and stuff like that on their home network as they are older and often need help. I’d like to be able to manage this remotely and want to do it securely normally I’d just put PFSense as the router in a VM and call it a day but I’ve already hooked them up with a Amplifi mesh system.

I’d like to setup a simple, secure ipsec site to site VPN without spinning up an entire router or anything crazy I know of two possible options being Strongswan and OpenVPN but the latter costing money unless there is a free opensource version.

Thanks for reading.

Edit: forgot to mention I have a UDM PRO to terminate the vpn tunnel at my house.

Why can’t you set up pfSense if you’re also running AmpliFi? You have a lot of options in the open source space for a router or VPN. My preference would be something employing IPsec or WireGuard.

Why not run Wireguard on the NUC itself? If you set it up to start automatically it’ll come up extremely quickly after boot. No need for port forwarding at your in-laws’ place, just at wherever you’re hosting the VPN server.

So you can’t get into the amplfi router and setup a tunnel like you can with USG and similar UI products?

Is Wireguard a No-Go?

I currently running openvpn (which is free if you host it) off of a raspi which works perfectly for me. There is an installer called pivpn which makes the setup process super easy.

Setup Wireguard on the NUC as a client connecting to your network. No need to configure anything on the Amplifi this way. You can also put PFSense in a VM and just disable all the services except VPN.

I’m not an expert but ZeroTier has been working for me.

  1. OpenVPN is free to use. Look at community version!

  2. WireGuard will give you the best performance and it’s easy to setup. We use centralized setup, where one peer works as server, but you can go meshy if you wish too.

  3. ZeroTier is good, even only as backup connection. It does have nice NAT punching features and interface on cloud which allows you for plenty networks.

+1 on this method

I’m using Opnsense with ZeroTier

Per ubquiti help page

The AmpliFi mesh system does not support any VPN software configurations on the router itself besides what AmpliFi Teleport offers. However, VPN software configured on your mobile devices or computers and not through the router itself should work on the AmpliFi network

My thought was prestige everything then ship and have it plugged in.

Sheesh, even fewer features than a cheapo Linksys or D-Link all in one.