Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.
Configuring the tunnel on the Linksys Web Interface
-
Open the Linksys management interface (typically 192.168.1.1)
-
In the left panel, select VPN, then select Gateway to Gateway
-
Fill in the following information:
.png?sv=2026-02-06&spr=https&st=2026-09-11T09%3A52%3A22Z&se=2026-09-11T10%3A03%3A22Z&sr=c&sp=r&sig=hUFz%2BQGMbqIkqLwYplLEusqlQMnrvOo7W0Np8d41iqs%3D)
Add a New Tunnel:
- Tunnel Name: Choose a name of your own choice.
- Interface: WAN1
Local Group Setup:
- Local Security Gateway Type: IP Only
- IP Address: Your external IP address (should be filled automatically)
- Local Security Group Type: Subnet
- IP Address: Enter the local IP address.
- Subnet Mask: Enter the subnet mask.
Remote Group Setup:
- Remote Security Gateway Type: IP Only
- IP Address: The IP of your NordLayer server with a dedicated IP
- Remote Security Group Type: Subnet
- IP Address: 10.6.0.0
- Subnet Mask: 255.255.240.0
- Continue to IPSec Setup and fill in accordingly:
.png?sv=2026-02-06&spr=https&st=2026-09-11T09%3A52%3A22Z&se=2026-09-11T10%3A03%3A22Z&sr=c&sp=r&sig=hUFz%2BQGMbqIkqLwYplLEusqlQMnrvOo7W0Np8d41iqs%3D)
- Keying Mode: IKE with PSK
- Phase 1 DHG: Group 5 (if your device supports Group 14, using that is recommended)
- Phase 1 Encryption: AES256
- Phase 1 Authentication: SHA1 (SHA256 is recommended)
- Phase 1 SA Lifetime: 28800
- PFS: Enabled
- Phase 2 DHG: Group 5 (if your device supports Group 14, using that is recommended)
- Phase 2 Encryption: AES256
- Phase 2 Authentication: SHA1 (SHA256 is recommended)
- Phase 2 SA Lifetime: 3600
- Pre-shared Key: Generate a pre-shared key (we will need this on our end as well)
Select Advanced. Enable Keep-Alive and set Dead Peer Detection Interval to 10 seconds. Leave the rest of the advanced settings with the default values.
.png?sv=2026-02-06&spr=https&st=2026-09-11T09%3A52%3A22Z&se=2026-09-11T10%3A03%3A22Z&sr=c&sp=r&sig=hUFz%2BQGMbqIkqLwYplLEusqlQMnrvOo7W0Np8d41iqs%3D)
Ending note:
In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.
- Pre-shared key - you can generate it or we can provide it
- Encryption details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
- Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
- Remote subnet and mask (the subnet is used in your local network)
Note: In case you have any questions or issues, press 'Chat with support' at the bottom of the page.