Setup Wireguard Peer Tunnel Manually

This experiment is ultimately for a home environment, but I want to R&D it at my business before implementing it at home. I already have a Proxmox server at my office with a Nethsecurity VM acting as a gateway to a few other VMs, one of which is an NS8 server. It’s all working beautifully, so I want to be cautious so as not to break a working system.

I am considering using a third party IPv4 static IP provider strictly for business from my home, which they claim I as a client can use by routing traffic behind my ISP’s modem using a Wireguard client tunneled to their Wireguard server. As is typical, my ISP provides a dynamic IP, which allows for everything on my home network to access the web, but now I want to host Nethsecurity and behind that, an NS8 server running Nextcloud and the Webserver, all while allowing the rest of my house to use the internet. In so many words, I’d like to isolate them, i.e., home usage and business usage.

I could use a small ethernet switch to connect my existing home router to my ISP’s modem and also connect the Proxmox (Nethsec and NS8 VMs) server to the modem, both sharing the dynamic IP address for traffic. I’m afraid if I route all traffic through the Wireguard client tunnel and then split off, it would slow streaming speeds to my home network.

For the business end using the Proxmox server, I was thinking use the wireguard client tunnel in a Nethsecurity VM, to establish the connection to the static IP, allowing all traffic through this connection, then port forward a/the Wireguard port using the 3rd party static IP address to a new wireguard server in the same Nethsecurity VM.

It’s starting to get fuzzy for me here, because then I would want to port forward http, https, and ssh to the NS8 VM’s LAN IP address, since it will sit behind the Nethsec VM. The end goal is to be able to access the servers on NS8 using domain(s) pointed at the 3rd party static IP address, which as I said, is really cloaked behind my ISP’s dynamic IP.

All that to say, does anyone have a howto, or can they throw together a howto, on how to accomplish this? My fear is the tunneled traffic speed would be greatly hampered using this method. Would a better way be to use ddclient on both the nethsec VM and also the NS8 VM, where I could access both UI’s through domain names, as well as Nextcloud and the Webserver and any virtual hosts within it? It seems like there’d have to be multiple ddclient configs to point the different domain names to a remote ddns like Cloudflare, but still, this sounds a little cleaner.

Any help, ideas, or critiques would be welcome.