Site-to-site
Connect LAN networks behind two private gateways.
Prerequisites#
Add the relevant LAN CIDRs to the Networks tab of each gateway. Source and destination gateways must differ.
Create a route#
- Open Network → Access → Site-to-Site.
- Add a policy and choose Allow or Deny.
- Select source gateway and network.
- Select destination gateway and network.
- Enable bidirectional initiation only when both sides require it.
- Set priority, set status, and save.
Current site-to-site policy applies to all protocols and all ports. Protocol and port controls are not enforceable restrictions in this release.
Expected result#
The selected gateway LANs route over encrypted tunnels according to direction and effect. This does not grant endpoint users access to services; endpoint-to-application grants remain under Access policies.