These are things I added post-install that I wish I had known about:

A) NAT/Routing Pollicies re: VPN to NOCIX:

  • If you're setting up a VPN connection for Site-to-Site connectivity, and a UniFi Router is on the CLIENT SIDE of the connection you MUST use a Routing Policy to get traffic to go out that port, otherwise the router won't know what the fuck to do.
  • For SIP connections (i.e. Gateways to PBX) you MUST setup firewall policies allowing inbound SIP Traffic on Port 5060 + 5080 and allow for RTP as well (16384-32768)

B) Site to Site:

  • NOCIX → PNET (SERVER → CLIENT) Wireguard
  • WITTNET → PNET (CLIENT → SERVER) Wireguard

That's about it.