← All posts

One door instead of many: remote access with WireGuard on a UniFi gateway

One door instead of many: remote access with WireGuard on a UniFi gateway

The first post in this series kept Beszel on the LAN, and the reasoning applies to a whole category of services: monitoring, admin panels, a password vault, anything meant for me and not the public. None of it belongs on the open internet. But I still need to reach it when I'm not sitting at home.

There's a wrong way to solve that and a right way. The wrong way is to expose each service one at a time, poking a new hole in the firewall for every dashboard you want to check from your phone. The right way is to stop reaching services out to the internet and instead bring yourself into the network. That's what a VPN does, and I run mine as WireGuard on the UniFi gateway.


One door instead of many

Picture the typical home network that grew over time: a port forward for the cameras, one for the NAS, one for the home-automation UI, one for a media server. Every one of those is a separate front door to the internet, and every one has to be hardened on its own, watched on its own, and patched on its own. Miss one and that's the way in.

A VPN collapses all of that into a single door. You open one well-understood entrance, prove who you are with a key, and from that point you're on the LAN. Every internal service is reachable by its normal local address, exactly as if you were home, and nothing extra is exposed to the outside world. It's the mirror image of the decision from the reverse-proxy post: the blog is public because it's meant for everyone, so it gets a hardened public door; everything else is meant for me, so it gets this private one.


Why WireGuard, and why on the gateway

WireGuard is the modern choice for this. It's fast, it's small, it uses key-based authentication, and it's quiet in a way that matters: the server never answers a packet that isn't signed by a known key, so from the outside the port looks dead. A scanner sweeping the internet finds nothing to talk to.

I run it on the UniFi gateway rather than in a container on the NAS, and that's a deliberate choice. The gateway already sits at the edge of the network, where the firewall and routing live. Terminating the VPN there means the tunnel ends at the border instead of on an internal host you'd have to forward a port to. It's one less container to maintain, and the device whose whole job is moving packets is the one doing it.


Prerequisites


Step 1: Create the WireGuard server

In the UniFi Network application, go to Settings, then VPN, then VPN Server, and choose Create New. Pick WireGuard as the type. The fields that matter:

Generate the key pair and apply. The gateway is now a WireGuard server.


Step 2: Add a client for each device

Back in the server's settings, add a client. UniFi generates that client's keys and hands you a configuration file plus a QR code.

Create one client per device rather than sharing a single config. It's slightly more setup, but it means you can revoke one phone or one laptop later without kicking everything else off the VPN.

On a phone, open the WireGuard app, add a tunnel, and scan the QR code. On a laptop, install the WireGuard client and import the downloaded config file. That's the entire client side.


Step 3: Connect and check

Toggle the tunnel on. You're now on your home network from wherever you are. Open an internal-only service by its normal local address, the same one you'd use at home, and it just loads. The Beszel dashboard from the first post is a good test: it never left the LAN, and now you can reach it from a café without it being exposed to anyone else in that café or anywhere else.

For advanced users: split tunnel vs full tunnel

The client's AllowedIPs decides what actually goes through the tunnel. A rough client config looks like this:

[Interface]
PrivateKey = <client-private-key>
Address = 192.168.5.2/32
DNS = 192.168.1.1

[Peer]
PublicKey = <server-public-key>
Endpoint = vpn.example.com:51820
AllowedIPs = 192.168.1.0/24    # split tunnel: only home traffic
# AllowedIPs = 0.0.0.0/0       # full tunnel: everything
PersistentKeepalive = 25

Split tunnel (route only your home subnet) is what I use day to day: your normal browsing and streaming stay on the local connection, and only traffic bound for home takes the tunnel. Full tunnel (0.0.0.0/0) sends everything through home, which is what you want on untrusted hotel or airport WiFi, where routing your whole session through your own network is the point.

For advanced users: dynamic IPs, CGNAT, and cellular

Two things break remote access before WireGuard even gets a say. First, a dynamic public IP: if yours changes, a hardcoded endpoint goes stale, so use a DDNS hostname as the endpoint and let it track the current IP. Second, CGNAT: some ISPs put you behind a shared public IP where inbound connections can't reach you at all. If that's your situation, a forwarded UDP port won't help, and UniFi's Teleport is the escape hatch. It's WireGuard underneath but doesn't need a public IP of your own. One smaller gotcha: on cellular, set PersistentKeepalive = 25 so the carrier's NAT doesn't quietly drop your tunnel between packets.


The one door still needs a good lock

Folding everything behind a single entrance is a big security win, but it also means that entrance matters more than any individual service did. Treat the client configs as secrets, because they contain keys. Keep one peer per device so a lost phone is a one-line revocation rather than a full key rotation. And keep the gateway's firmware current, since it's now the thing standing between the internet and your entire LAN. WireGuard's silence buys you a lot, but the key hygiene is on you.


The pattern, both halves

Across four posts the decision has always been the same one, asked twice. Should this be reachable by everyone? If yes, it gets the full public treatment: DNS, a reverse proxy, TLS, and CrowdSec watching the door. If no, it stays on the LAN and I reach it through one private door instead, WireGuard on the gateway, with nothing else exposed.

That's the whole model. One hardened public entrance for the things meant to be found, one key-only private entrance for the things meant for me, and a clear rule for deciding which is which. Once you're inside that private door, the next question is how to manage a handful of machines at once without juggling them by hand, which is where I'll go next.

Running WireGuard somewhere other than a UniFi box, or stuck behind CGNAT? Reach out to me and I'll fold the good cases into a later post.

Moreno De Zorzi
Moreno De Zorzi More about me →