Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 1170

Site-to-Site VPN

Reviewed byCybersecurity entrepreneur & security researcher

What is Site-to-Site VPN?

Site-to-Site VPNA persistent encrypted tunnel between two networks — typically branch offices, data centers, or cloud VPCs — that lets hosts on each side reach each other transparently.


A site-to-site VPN connects two routed networks through gateways that build a cryptographic tunnel across an untrusted network, so endpoints behind them communicate as if directly linked. Implementations are most often IPsec in tunnel mode, sometimes complemented by GRE or modern alternatives like WireGuard.

The dominant stack is IPsec, defined by RFC 4301 (Security Architecture for IP). Key exchange uses IKEv2 (RFC 7296), which negotiates an IKE SA and then one or more Child SAs; data is carried by the Encapsulating Security Payload, ESP (RFC 4303), which encrypts and authenticates each packet. Configuration means matching cryptographic suites on both peers, defining traffic selectors (which subnets are tunneled), and exchanging pre-shared keys or X.509 certificates, with Dead Peer Detection and rekey timers keeping the tunnel healthy.

A classic weakness is the legacy IKEv1 aggressive mode with a pre-shared key: the responder sends a hash of the PSK before the exchange is encrypted, letting an attacker who captures it run an offline dictionary attack (tools such as ike-scan and hashcat mode 5300 automate this). Certificate authentication or IKEv2 avoids that exposure. WireGuard offers a leaner alternative built on the Noise protocol framework and Curve25519, with a far smaller codebase. Site-to-site VPNs are heavily used for hybrid-cloud connectivity, branch-to-headquarters links, and disaster recovery, often paired with dynamic routing (BGP) for failover.

flowchart LR
  subgraph SiteA[Site A 10.0.0.0/24]
    HA[Internal host] --> GA[VPN Gateway A]
  end
  subgraph SiteB[Site B 10.1.0.0/24]
    GB[VPN Gateway B] --> HB[Internal host]
  end
  GA -->|IKEv2 negotiation| GB
  GA -->|ESP tunnel over Internet| GB

● Examples

  1. 01

    An IPsec tunnel linking an on-premises data center to an AWS VPC for hybrid workloads.

  2. 02

    Multiple branch offices linked to headquarters via IKEv2 tunnels with BGP failover.

● Frequently asked questions

What is Site-to-Site VPN?

A persistent encrypted tunnel between two networks — typically branch offices, data centers, or cloud VPCs — that lets hosts on each side reach each other transparently. It belongs to the Network Security category of cybersecurity.

What does Site-to-Site VPN mean?

A persistent encrypted tunnel between two networks — typically branch offices, data centers, or cloud VPCs — that lets hosts on each side reach each other transparently.

How do you defend against Site-to-Site VPN?

Defences for Site-to-Site VPN typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Site-to-Site VPN?

Common alternative names include: Gateway-to-gateway VPN, Network-to-network VPN.

● Related terms

● See also