Skip to content

Site-to-site VPN between two office locations.

Two firewalls with IPsec or WireGuard between them, one pipe between networks. Works fine, but do not underestimate how often NAT, asymmetric routing or MTU issues ruin your day.

Try this first

  1. 1Both offices must have different internal subnets or you have overlap and nothing routes.
  2. 2Choose IKEv2/IPsec or WireGuard depending on what both firewalls support, do not use IKEv1.
  3. 3Add routes on both sides and verify with ping and traceroute from both directions, often it works one way only.
  4. 4Set tunnel MTU to 1380 or 1400 to avoid fragmentation, especially with PPPoE-based providers.

When to bring us in

More than two sites or new branches added regularly: do not build a mesh of site-to-site, deploy SD-WAN or a Tailscale subnet router.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.