I'm really confused why this creates an IPsec server AND an wireguard server, or do I read that wrong? Managing two server which basically do the same thing seems to double the attack surface without any gains. One selling point of wireguard is to be an easier but still as least as secure alternative to IPsec.