--- title: "Setting up site-to-site on Untangle | Nordlayer HelpNG" slug: "site-to-site-untangle-ng" status: "update" updated: 2026-09-08T13:08:20Z published: 2026-09-08T13:08:20Z canonical: "help.nordlayer.com/site-to-site-untangle-ng" --- > ## Documentation Index > Fetch the complete documentation index at: https://help.nordlayer.com/llms.txt > Use this file to discover all available pages before exploring further. # Setting up site-to-site on Untangle NG **Note**: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead. 1. On the Apps page install the Application IPSec 2. Enable the IPsec VPN application ![Untangle NG Firewall IPsec VPN status dashboard showing 3 configured tunnels with enabled service toggle](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/01%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Create a new IPSec Tunnel by selecting Add ![Untangle NG IPsec Tunnels tab showing Add button with table columns for tunnel configuration](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/02%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Fill in the information as seen in the image below. Please generate a Pre Shared Secret Key (we will also need this value on our end) 2. Select Done and then Save 3. Check the Tunnel Status; it should be Active ![Untangle NG IPsec status showing active VPN_NordLayer tunnel with network addresses and traffic statistics](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/03%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Select Add to create a rule to allow the connected clients to access the internal LAN ![Untangle NG Firewall Rules tab showing Add button with routing and port forwarding notice](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/04%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Add the LAN subnet of the address the NordLayer tunnel side will provide (10.6.0.0/20) ![Untangle NG firewall rule editor showing NordLayer LAN In pass rule with source address condition](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/05%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Enable the rule by selecting Done ![Untangle NG IPsec tunnel configuration showing VPN_NordLayer with IKE settings and preshared key authentication](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/06%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) 1. Select Save to apply the new rule ![Untangle NG dialog box showing Save button with floppy disk icon highlighted](https://cdn.document360.io/fc1049cd-8f71-4b89-b9b8-dbca9fdcdd16/Images/Documentation/07%20Setting%20up%20site-to-site%20on%20Untangle%20NG(1).png) ## Ending note: In order to finalize the site-to-site tunnel, please create a setup in [Sites tab of the NordLayer Control Panel](/v1/docs/site-to-site). - Pre-shared key - you can generate it or we can provide it - Encryption  details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2) - Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP) - Remote subnet and mask (the subnet is used in your local network) --- **Note**: In case you have any questions or issues, press '**Chat with support**' at the bottom of the page.