Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.
Configuring the tunnel on the Netgear Management Interface
-
Open the Netgear management interface
-
In the left panel, select Security, then select IPSec VPN
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- Select the Add to create a new profile
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- Fill in the following information:
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- Policy Name: Create the name of your own choice.
- Mode: Net-2-Net
- Remote Gateway IP: Enter the IP address of your NordLayer server with a dedicated IP.
- Local Subnet and Local Mask: Enter your LAN subnet and subnet mask.
- Remote Subnet: Enter 10.6.0.0
- Remote Mask: 255.255.240.0
- Generate a pre-shared key (we will also need this value on our end) and choose IKEv2
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- At the Advanced Settings fill in the following information:
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- Phase 1 Proposal: sha1-aes256-dh5 (sha256-aes256-dh14 highly recommended)
- Exchange Mode: main
- Negotiation Mode: Initiator
- Phase 1 SA Lifetime: 28800 seconds
.png?sv=2026-02-06&spr=https&st=2026-09-11T11%3A00%3A13Z&se=2026-09-11T11%3A11%3A13Z&sr=c&sp=r&sig=AJCTABNGvTy5ta9unReAguSZkugleRduWyvYPY2GipA%3D)
- DPD: Enable
- DPD Interval: 10 seconds
- Encapsulation Mode: Tunnel Mode
- Proposal (Phase 2): esp-sha1-aes256 (esp-sha256-aes256 highly recommended)
- SA Lifetime (Phase 2): 3600 seconds
Ending note:
In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.
- Pre-shared key - you can generate it or we can provide it
- Encryption details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
- Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
- Remote subnet and mask (the subnet is used in your local network)
Note: In case you have any questions or issues, press 'Chat with support' at the bottom of the page.