Either use bare wireguard or netbird/zerotier/tailscale.
does it open the port to the internet, for anyone to see or connect to?
Yes, it will be accessible on the local network if incoming connections to your port are not blocked by a local AP or switch, and from the internet if incoming connections to you are also not blocked at the router.
It’s generally a bad practice to expose apps (syncthing, etc) directly to the internet with
allow from anywhere
rules, but it’s not an issue for services like wireguard and ssh when used properly.


Protests armed by the US, per Trump