These are things I added post-install that I wish I had known about:
A) NAT/Routing Pollicies re: VPN to NOCIX:
- If you're setting up a VPN connection for Site-to-Site connectivity, and a UniFi Router is on the CLIENT SIDE of the connection you MUST use a Routing Policy to get traffic to go out that port, otherwise the router won't know what the fuck to do.
- For SIP connections (i.e. Gateways to PBX) you MUST setup firewall policies allowing inbound SIP Traffic on Port 5060 + 5080 and allow for RTP as well (16384-32768)
B) Site to Site:
- NOCIX → PNET (SERVER → CLIENT) Wireguard
- WITTNET → PNET (CLIENT → SERVER) Wireguard
That's about it.

