Thanks for the comments. I have just found it is smart, straight forward to set up and can be always on or not, depending on what you use it for.
I have used server to server VPN previously - openvpn, but found it difficult to just run workstation to server, don't recall why.
I tried IPSEC also, but had a hell of a time trying to setup the connections and gave up. Admittedly, this was 5 years ago!
I generally settled with tunnelling through an SSH connection to get RDP running on Windows.
Anyway, Wireguard works out of the 'box' (kernel) with a fairly simple key exchange, etc.
I am not concerned about the time for this to happen with the smeserver, just intrigued about whether it could be done.
Cheers.