Documentation Index

Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt

Use this file to discover all available pages before exploring further.

Setting up site-to-site on Untangle NG

Prev Next

Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.

  1. On the Apps page install the Application IPSec

  2. Enable the IPsec VPN application

Untangle NG Firewall IPsec VPN status dashboard showing 3 configured tunnels with enabled service toggle

  1. Create a new IPSec Tunnel by selecting Add

Untangle NG IPsec Tunnels tab showing Add button with table columns for tunnel configuration

  1. Fill in the information as seen in the image below. Please generate a Pre Shared Secret Key (we will also need this value on our end)

  2. Select Done and then Save

  3. Check the Tunnel Status; it should be Active

Untangle NG IPsec status showing active VPN_NordLayer tunnel with network addresses and traffic statistics

  1. Select Add to create a rule to allow the connected clients to access the internal LAN

Untangle NG Firewall Rules tab showing Add button with routing and port forwarding notice

  1. Add the LAN subnet of the address the NordLayer tunnel side will provide (10.6.0.0/20)

Untangle NG firewall rule editor showing NordLayer LAN In pass rule with source address condition

  1. Enable the rule by selecting Done

Untangle NG IPsec tunnel configuration showing VPN_NordLayer with IKE settings and preshared key authentication

  1. Select Save to apply the new rule

Untangle NG dialog box showing Save button with floppy disk icon highlighted

Ending note:

In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.

  • Pre-shared key - you can generate it or we can provide it
  • Encryption  details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
  • Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
  • Remote subnet and mask (the subnet is used in your local network)

Note: In case you are experiencing different results, make sure that you have you carefully gone through all the steps. Having said that, in case the issue persists please feel free to contact our 24/7 customer support team.