Skip to content →
Log in

Site-to-site

Connect LAN networks behind two private gateways.

Prerequisites#

Add the relevant LAN CIDRs to the Networks tab of each gateway. Source and destination gateways must differ.

Create a route#

  1. Open Network → Access → Site-to-Site.
  2. Add a policy and choose Allow or Deny.
  3. Select source gateway and network.
  4. Select destination gateway and network.
  5. Enable bidirectional initiation only when both sides require it.
  6. Set priority, set status, and save.

Current site-to-site policy applies to all protocols and all ports. Protocol and port controls are not enforceable restrictions in this release.

Expected result#

The selected gateway LANs route over encrypted tunnels according to direction and effect. This does not grant endpoint users access to services; endpoint-to-application grants remain under Access policies.