• FauxLiving@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 hours ago

    You only have to give them access to a specific port on a specific machine, not your entire LAN.

    My VPN has a ‘media’ usergroup who can only access the, read-only, NFS exports of my media library.

    If you’re just installing Wireguard and enabling IP forwarding, yeah it would not be secure. But using a mesh VPN, like Tailscale/Headscale, gives you A LOT more tools to control access.