I can’t remember what it is, but there is some limitation with Wireguard. I’ll have a look when home but probably a bit off topic if it’s not the per device VPN feature.
Cheek is an understatement, that said I wouldn’t disagree that the basic subscription offers reasonable value and even the free version is OK for what it does, but like you it frustrates me that wireguard is a top tier paid option, but it’s Arista’s party.WireGuard is unique in that it's deliberately coded as 'just another (unix) network interface'. You can literally make it do anything you like - policy based routing, source/destination based routing, per-client routing... Whether Untangle expose that in a GUI is, of course, another matter. I think they have a cheek charging $150 a year for not disabling access to a completely FOSS project with less than 2k lines of code, though!
It was always a top tier feature from its introduction prior to the buy out, but it’s now 100% an Arista choice on what they do, admittedly I would imagine it’s pretty low on the list of things they may want to look at - I would imagine home user subscriptions account for very little in terms of turnover.It was a top tier prior to the acquirement, so it’s nothing to do with Arista. I guess what you’re paying for is having it packaged up into a nice to use GUI.
It’s not just that they only bundled it into the top tier version, they actually did a fairly poor job of integrating it. When I read the post from @ChrisD. above I immediately thought “yep, another Wireguard issue”.
With what you're wanting to achieve, just opt for one of these options. Pros and cons with either of these but, depending on the hardware you opt for, option 1 could be a bit of a learning curve* to setup compared to a per-device approach but could work out more cost effective (depends on the number of devices than need VPN access that require additional hardware) whilst offering a bit more flexibility.OK, so let me get this right:
Option 1: Single device for routing, switching (not really my need), wireless with VPN tunneling in the hardware
Option 3: Router with Wifi, VPN via software