Wireguard Best Approach (two non-public sites)?

Including fedx and gst to my door cdn 572 ...

@Amm0 you should look at Grok because IMO Grok has mastered RouterOS ... :slightly_smiling_face: the clearer the requirements the superior will be the results ... I use Grok expert mode ...

Except there is no AI needed here....

Nothing changes that UDP on a specific known port is needed for WG connection.

The question is assuming no custom STUN/TURN tricks, like BTH (or TailScale, etc). And if we assume "non-public" means some kinda CGNAT (and not SOCKS/similar proxy or some HTTP/S only firewall, etc)... That gets you to @CGGXANNX highlights that answer to @anav's question depends on the exact type CGNAT employed, and then only if CGNAT uses some fixed block of ports on a static IP upstream to even being able to have "two non-public sites". Some CGNATs are more dynamic in port assignment, so you'd have no hope if that's how the CGNAT is setup.

If you have IPv6 available on both side, that should be the plan. If IPv6 is available only on one, that be possible but then talking about tunnel brokers etc. And with DDNS used on WG with IPv6, that be way more stable than say having to rely on the ISP CGNAT design not changing for something like a site-to-site.

Turns out OP reveal he as at least one end with public IP access through ISP router so no shenanigans needed but the discussion reveals a tenable ipv4 solution with BTH on the arm device, and setting up a user to be a router with some tricks.

@anav , How did you go with that? Any luck?

Didnt pursue it in the end as the OP did have a reachable WANIP.