User Manual

USER MANUAL
Peplink Balance Series
http://www.peplink.com - 66 / 182 - Copyright © 2011 Peplink
12 Site-to-Site VPN
(Available on Peplink Balance 210+)
Peplink Balance Site-to-Site VPN functionality securely connects one or more branch offices to your
company's main headquarters or to other branches. The data, voice, or video communications between
these locations are kept confidential across the public Internet.
The Site-to-Site VPN of the Peplink Balance is specifically designed for multi-WAN environment. The
Peplink Balance can aggregate all WAN connections’ bandwidth for routing Site-to-Site VPN traffic.
Unless all the WAN connections of one site are down, the Peplink Balance can still maintain VPN up and
running.
VPN Bandwidth Bonding is supported in firmware 5.0+. All available bandwidth will be utilized to establish
the VPN tunnel, and all traffic will be load balanced at packet level across all links. VPN Bandwidth
Bonding is enabled by default.
Tip
You can define firewall rules to control access within the VPN network. Outbound traffic can be redirected and go
through VPN tunnels with custom outbound policies, please refer to section 13 for details
12.1 Site-to-Site VPN Settings
Peplink Balance 380, 580, 710 and 1350 support making multiple Site-to-Site VPN connections with a
remote Peplink Balance 210, 310, 380, 580, 710, 1350, or a Pepwave MAX Mobile Router. Peplink
Balance 210 and 310 support making two Site-to-Site VPN connections with a remote Peplink Balance
210, 310, 380, 580, 710, 1350, or a Pepwave MAX Mobile Router.
Peplink Balance that supports multiple VPN connections can act as a central hub which connects branch
offices. For example, branch office A and branch office B make VPN connections to headquarters C,
both branch offices’ LAN subnet and subnets behind it (i.e. static routes) will also be advertised to the
headquarters C and the other branches. So branch office A will be able to access branch office B via
headquarters C in this case.
The local LAN subnet and subnets behind the LAN (defined under Static Route in the LAN settings page)
will be advertised to the VPN. All VPN members (branch offices and headquarters) will be able to route
to the local subnets.
Note that all LAN subnet and subnets behind it have to be unique. Otherwise, VPN members will not be
able to access each other.
All data can be routed over the VPN with 256-bit AES encryption standard.
To configure, navigate to Network > Site-to-Site VPN: