No, just one. You set up one device/server as a VPN gateway (often called VPN concentrator), and you will have access to anything the concentrator has access to on your home network.
Either you use your VPN concentrator as your jump box, or you set up routing and firewalls to be able to access them directly.
Any system beyond a vanilla install will need some tweaks to fit your use case(s). And these tweaks often end up as a stack of glass boxes over time, unless meticulously planned and purpose built from the beginning.
As long as it’s manageable and secure, don’t let “perfect” be the enemy of “operational”.
Wanting to rebuild from scratch is pretty common. The question is whether you need to and should. You have to weigh cost and work hours up against any benefits to figure out the answer.