We’re excited to announce that Site to Site feature is available now.
It allows offices in multiple locations to establish secure connections with each other over internet. It extends the company’s network, making computers resources from one location available to employees at other locations.
Senerio 1: A company has dozens of branch offices that they wish to join in a single private network to share resources.
Senerio 2: A company has a close relationship with a partner company, the Site to Site allows the companies to work together in a secure, shared network environment while preventing access to their separate internets.
Senerio 3: A family has IP camera and when they are not at home, the Site to Site allows to remote access the IP camera.
One of the locations has a public static(or dynamic) ip, and two or more GL-iNet devices with v3.026
So it’s a VPN server with clients connecting to it?.. How is this any different than just configuring OpenVPN server on one device then VPN clients on the other two? Or is the goal to just “simplify” the process of doing that?
Technically it is vpn server and client. We are using Wireguard, not openvpn.
But they are very different, in the following aspects:
VPN client and server set up is complicated. So you have to set up server, get the config and set up client. Most people cannot get this done within 30 minutes. We Site2Site you can do this in minutes.
It is about routing. Site2Site only links two networks into one. Each network will still have its own Internet. This is very different from a client/server concept which client’s Data will all go through the server.
It is about automation. So you do not need to configure server then client. You can just create a network via cloud and all will be set up. And you can monitor the connections.
I is about business concept. Linking multiple offices in different locations is not a technical concept, but rather business concept and it addresses productivity.
So all applications is some tools/platform/UI that is based on basic IT technologies.
I have a question: Does your HDHomeRun client needs to use a IP address to access the NAS?
For example, if you NAS is 192.168.1.5 and your tablet’s IP is on another router while having an IP 192.168.8.11, can the HDHomeRun work?
If yes then Site2Site is the correct way for you.
If you can set up Wireguard by yourself and set up the correct routing, then you can use that.
No cloud needed.
It is a great satisfaction for tech guys to DIY their own solution.
Too complicated. Even for one with good skills, it takes 30 minutes to configure everything.
If you failed to configure your server before you leave home, then you cannot do it on your travel.
Coping with routing is difficult. By default all your data goes to your home. So your internet is may be throttled.
But if you use Site2Site, you do not need to worry about setting up sever and client.
As long as you have the correct firmware, you can set up this in minutes. Server and client config will be distributed automatically.
You can set this up on your way. So if you failed to make it work before leaving home, you can set up anytime.
Your Internet data and your NAS access is in different route. So your Internet may not be throttled.
You can monitor how much data you used. There is only simple monitoring including totally traffic transmitted.
If you ISP changed your IP address, the Site2Site network will self-heal itself.
You have to use our Cloud to config this. Although we do not store any of your config and data, some users still have privacy concerns.
Now the default routing policy is splitting Internet and in-site access. So if you want to use vpn to protect your privacy this may not work for you now. But this is just routing policy so we will cope this later.
I don’t want this announcement thread to become my own private tech support channel, so please move this to a different thread if you think it is best.
As to your question, I don’t know. I have only tried this when my tablet and NAS are on the same subnet. I don’t think setting up a VPN client and server would be hard for me, but my assumption was that, by default, clients would be put in a different subnet than the server’s DHCP space. Perhaps there is an easy routing rule to handle this, but I have not figured that out. Any pointers to resources? Alternatively, is it better to force the VPN client to live in the same subnet as my home has?
To do this, you may need layer 2 bridging. Openvpn tap can do this job. Or a GRE tunnel.
We do not have this set up in the UI, but some people do this. Using Layer2 bridge, your device will be a client of you home network and all data goes there.
Mon Nov 11 11:27:57 2019 Initialization Sequence Completed
Mon Nov 11 11:27:57 2019 MANAGEMENT: >STATE:1573468077,CONNECTED,SUCCESS,10.8.0.6,188.8.131.52,1194,
this is the screenshot of the Tunnel IP Adress Range:
Turn off openvpn client in your phone, connect your phone connect AR750 Slicher wifi, can your phone access 192.168.18.1 ?
What do your mean “not #2” in “I can reach via Android -Phone Open-VPN client Lokation #1 (Master) but not #2.”?
Your phone run openvpn client to connect to Location #1(AR750 Slicher), then you try to access AR750 Conway by access 192.168.18.1?
actualy I am at CONWAY location (#2) without Open VPN I can reach 192.168.18.1 and 192.168.17.1 as well. I can’t reach 192.168.9.x adresses . If I run OPen VPN Client I can reach 192.168.9.x adresses in SILCHER location.
Should this be possible in Site to Site connection? Even this I’m missing. I tought, that this need OpenVPN.
then will that not acceptet (adress conflict guest net)
“What do your mean “not #2” in “I can reach via Android -Phone Open-VPN client Lokation #1 (Master) but not #2.”?” this means, that when I run OpenVPN Client in mobile network I can reach 192.168.9.x adresses in SILCHER location (as in 1)) and even not AR750 Conway by access 192.168.18.1.
“Your phone run openvpn client to connect to Location #1(AR750 Slicher), then you try to access AR750 Conway by access 192.168.18.1?” even this is not possible.
Outside SILCHER and CONWAY I can reach via OpenVPN only SILCHER an not CONWAY.