Beginner's VPN question - MT to MT

I have MT in office as main router (192.168.33.1)
I need to give outside person access to our VOIP server (192.168.33.31)
I got small hAP router.

Here is what I want to happen:

  • User will connect router to internet
  • Router will auto-connect to our network
  • Phone will be connected to router and will register with our PBX

Questions:

  1. What kind of VPN/tunnel is the best for what I want? Lightest/fastest with full obfuscation of traffic so we don’t have any NAT issues, etc.
  2. How do I make sure that this user will not have access to anything in our network but this PBX server?
  3. I want to be able to connect to both router and phone on other end (manage router settings and provision phone/settings) from inside our office