Me and my friend have an identical setup at our houses: Windows server VM with a drive we use for media, nextcloud, photos on our local network…

The idea is to create a backup folder on the drive that I will share with him and he with me which we will mount and where we’ll upload backups of documents and other important files like immich library and it must be encrypted so we don’t have access to each others files.

From my research we would use Tailscale as VPN and Veeam for creating encrypted incremental backups. (It’s possible right?)

Is this an optimal setup + can we setup tailscale so the connection is only between the two servers without access to the whole network?

Also how to setup access to the shared folder? We would have to create users for each other or set the folder permissions to rw for everyone right?

Thanks for any suggestions.