A site-to-site VPN creates an encrypted tunnel over the internet between each office’s routers, so the networks appear as one. The most used technologies are IPsec, the classic standard supported by almost all equipment, and WireGuard, more modern, faster and simpler to configure. The same VPN gives remote access to people working from home.
WireGuard or IPsec
| Aspect | WireGuard | IPsec |
|---|---|---|
| Age | Modern | Classic standard |
| Configuration | Simple, with key pairs | More complex, with many options |
| Performance | Very high | High, depending on equipment |
| Compatibility | Recent routers and phone and computer apps | Practically all routers and firewalls |
| When to use | Between devices that support it and for remote work | When one end only supports IPsec |
Good practice
- Avoid overlaps: each site must use a different address range.
- Give each remote user their own key and revoke it when they leave.
- Allow only necessary traffic between sites: not everything needs to see everything.
- Do not publish camera, NAS or automation ports: reach them through the VPN.
- Monitor tunnel status and get alerted if one drops.