Offices Wireguard tunnel and network access

Having different ports for the local and remote devices is not an issue, it is in fact simpler to let the remote pick a random one.
I have been burned by fixed ports on the initiator in previous versions 51820 was added by default. You have to be very careful to choose different ones if you have more than one wg tunnel.
For a concrete case, look at this [topic.] (Subtle wireguard configuration errors)
The “Listen port” field is now optional. If empty the default “option listen_port ‘51820’” line isn’t added anymore in the configuration.