How to setup site-to-site VPN with WFilter’s SD-WAN service?

WFilter’s SD-WAN service is an integration of the ZeroTier networking. With SD-WAN, you are able to build secure site-to-site VPN tunnels without needing a static public IP address.  This guide will show you the necessary steps using WFilter NGF.

1. Network topology

202202161644989114139685

As shown in the above topology diagram, headquarter and two branches all use WFilter NGF as gateway. By adding each gateway into the SD-WAN network, you will be able to setup secure site-to-site VPN tunnels.

2. SD-WAN subnet settings

First setup a SD-WAN network in the WFilter cloud service.

Sdwan network01.png

Sdwan network02.png

3. Join every WFilter into the SD-WAN network

QQ20250707-145422

4. Assign SD-WAN ip and setup routing

QQ20250707-145655

Assign static SD-WAN ip addresses to every WFilter, for example: WFilter A(10.200.188.1), WFilter B(10.200.188.2), WFilter C(10.200.188.3). Then you can setup SD-WAN routing policy to forward LAN traffic.

QQ20250707-150606

After the above setups, each local area network can directly access each other. To restrict access, you also can setup firewall rules in WFilter’s firewall->Rules.