Quote from: ludarkstar99 on January 14, 2026, 12:28:34 PMWill I be able to set up a VPN gateway with double NAT?
Yes. As long as the ISP-provided combo router allows you to configure a DMZ or perform port forwarding to your firewall, this will work. OpenVPN, in particular, works very well in this type of setup and is usually the easiest option.
Am I okay with double NAT if my OPNsense LAN uses something like 192.168.0.x or 192.168.1.x?
yes.
Since I don't want to buy an additional access point, I plan to connect my laptop to the ISP router's guest Wi-Fi and then use the VPN to access the rest of the network (rsync, cloud access, remote development, pulling compiled packages, etc.). Is this fine, or is there a better approach?
That's a perfectly valid and straightforward approach. The VPN will give you access to internal hosts and services without requiring complex port-forwarding rules.
-----
Regarding individual port forwarding: the behavior is exactly as you described. Port forwards expose only specific services, while the DMZ forwards all unsolicited inbound traffic to a single internal address (your firewall?).
Personally, I tend to use the DMZ approach. It allows the firewall to block unwanted connections centrally and provides data for my SIEM. That said, forwarding only specific ports is also perfectly fine and will work as expected.
First of all, thank you for your answers and your time :)
With those answers I'll happily gonna take the next steps and order a NUC (I'm planning to go N100 as i heard N150 is not really that worth it). I guess now it'll be time for tinkering even though I will leave this thread a couple of days unsolved in case any other opinions come in! ':D
"