Run Wireguard on router, or on Home Assistant server?

I am running WG on the OpenWRT router:

  • The attack surface of a WG server is minimal (look into its architecture)
  • Gives me remote access to the LAN (occasionally helpful)
  • Simplifies firewalling and saves me from port forwarding
  • One less thing to fail on the HA machine
  • Somewhat random: my router has more compute than my HA Green, either way, speed is unlikely to matter

So far I have not added Nabu Casa so to minimize the attack surface.

2 Likes