Guides

Site-to-site VPN and remote access

A business with two offices, a warehouse or staff at home needs everyone to reach the same resources without opening the network to the internet. That is what a VPN is for.

Domotica Valencia · Updated:

In short

A site-to-site VPN creates an encrypted tunnel over the internet between each office’s routers, so the networks appear as one. The most used technologies are IPsec, the classic standard supported by almost all equipment, and WireGuard, more modern, faster and simpler to configure. The same VPN gives remote access to people working from home.

WireGuard or IPsec

VPN technology comparison
AspectWireGuardIPsec
AgeModernClassic standard
ConfigurationSimple, with key pairsMore complex, with many options
PerformanceVery highHigh, depending on equipment
CompatibilityRecent routers and phone and computer appsPractically all routers and firewalls
When to useBetween devices that support it and for remote workWhen one end only supports IPsec

Good practice

  • Avoid overlaps: each site must use a different address range.
  • Give each remote user their own key and revoke it when they leave.
  • Allow only necessary traffic between sites: not everything needs to see everything.
  • Do not publish camera, NAS or automation ports: reach them through the VPN.
  • Monitor tunnel status and get alerted if one drops.

Frequently asked questions

Do I need a fixed IP?

It helps but is not always essential: a dynamic domain name can be used. If both sites are behind CGNAT, another solution is needed, such as an intermediate server.

Which equipment supports it?

Professional routers such as MikroTik support WireGuard and IPsec without extra licences. Many other brands’ gateways also include VPN.

Contact

Shall we talk about your project?

Tell us what you need and what stage you are at. We will get back to you to arrange a site survey or a proposal.

+34 605 660 658 info@domoticavalencia.es Valencia and metropolitan area