I am looking to add VPN server on the LAN side of some hAP devices. So far RPIs are the choice, but I would prefer not to had another device on the network.

Is possible or could it be possible to run a VPN server from the hAP without breaking AREDN functions ? This would allow to feed internet to selected devices inside the mesh with some control and without adding another device.
 This has been mentioned a few times in the forums, but called a 'proxy' server.    Yes, this is possible. 

