I've already made positive experiences with SSH tunnels. Although Wireguard seems to be the way to go at the moment. Especially as WG will (finally) be included in the Linux kernel. In the beginning I will run both parallel. Just to be sure.
Thank you for your reply!