--- title: "Setting up site-to-site on Netgear BR500 router" slug: "site-to-site-netgear-br500-router" description: "Using the Netgear management interface, configure the VPN using the Net-2-Net Remote Gateway IP.If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead." status: "update" updated: 2026-09-08T13:10:07Z published: 2026-09-08T13:10:07Z canonical: "help.nordlayer.com/site-to-site-netgear-br500-router" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt > Use this file to discover all available pages before exploring further. # Setting up site-to-site on Netgear BR500 router **Note**: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead. ## Configuring the tunnel on the Netgear Management Interface 1. Open the Netgear management interface 2. In the left panel, select Security, then select IPSec VPN ![Netgear router navigation menu with IPsec VPN option highlighted under Security section](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/01%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) 1. Select the Add to create a new profile ![Netgear IPsec VPN policy list showing empty table with add, delete, and refresh buttons](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/02%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) 1. Fill in the following information: ![Netgear IPsec VPN policy configuration form showing NordLayer name with network-to-network mode selected](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/03%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) - **Policy Name**: Create the name of your own choice. - **Mode**: Net-2-Net - **Remote Gateway IP**: Enter the IP address of your NordLayer server with a dedicated IP. - **Local Subnet and Local Mask**: Enter your LAN subnet and subnet mask. - **Remote Subnet**: Enter 10.6.0.0 - **Remote Mask**: 255.255.240.0 1. Generate a pre-shared key (we will also need this value on our end) and choose IKEv2 ![Netgear pre-shared key input field with IKEv2 protocol selected for VPN authentication](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/04%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) 1. At the Advanced Settings fill in the following information: ![Netgear Phase-1 advanced settings showing proposal sha1-aes256-dh5 with main mode and initiator configuration](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/05%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) - **Phase 1 Proposal**: sha1-aes256-dh5 (sha256-aes256-dh14 highly recommended) - **Exchange Mode**: main - **Negotiation Mode**: Initiator - **Phase 1 SA Lifetime**: 28800 seconds ![Netgear Phase-2 VPN settings showing DPD enabled with esp-sha1-aes256 tunnel mode and 3600 second lifetime](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/06%20Setting%20up%20site-to-site%20on%20Netgear%20BR500%20router(1).png) - **DPD**: Enable - **DPD Interval**: 10 seconds - **Encapsulation Mode**: Tunnel Mode - **Proposal (Phase 2)**: esp-sha1-aes256 (esp-sha256-aes256 highly recommended) - **SA Lifetime (Phase 2)**: 3600 seconds ## Ending note: In order to finalize the site-to-site tunnel, please create a setup in [Sites tab of the NordLayer Control Panel](/v1/docs/site-to-site). - Pre-shared key - you can generate it or we can provide it - Encryption  details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2) - Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP) - Remote subnet and mask (the subnet is used in your local network) --- **Note**: In case you have any questions or issues, press '**Chat with support**' at the bottom of the page.