How to Set Up Site-to-Site VPN Between QNAP Routers
Applicable Products
QHora-301W
QHora-321
QHora-322
QMiro-201W
QMiroPlus-201W
QuWAN Auto-Mesh VPN Guide
By using two QNAP routers, you can easily connect two different locations, allowing devices at both sites to communicate seamlessly as if they were in the same office.
Before configuration, please organize your network connections as follows:
Simply add both devices to the QuWAN Orchestrator, and the system will automatically establish a Site-to-Site VPN connection for you. This approach not only simplifies the deployment process but also enables unified configuration and centralized management across locations through the QuWAN interface.
1. Network Deployment Strategy
Hub Site (Core Station): Connect your Public IP to the WAN port of this QHora router. This device will act as the "lighthouse" for the connection.
Edge Site (Branch Station): This device does not require a public IP. It will function correctly as long as it has a standard internet connection (even behind a modem or firewall).
Pro Tip: Assigning the Public IP to the Hub ensures that the Edge device can always "find its way home" regardless of its local network environment, automatically establishing a stable connection.
2. Configuration Steps
Step 1: Log in and Enable QuWAN
Log in to the management interface of both routers and navigate to the QuWAN menu:
- Ensure both devices are logged in using the same QNAP ID.
In the Organization selection, choose the default "My Organization". Using the default setting makes the process faster and easier!
Step 2: Configure the Hub (The device with a Public IP)
Set the device role to Hub.
The system will automatically detect the Public IP on the WAN port and register it with the cloud Orchestrator.

Step 3: Configure the Edge (The second device)
Set the device role to Edge.
Verify IP Segments: To avoid connection conflicts, ensure that the LAN IP ranges of the two devices do not overlap.
Example: If the Hub uses
192.168.1.x, set the Edge to192.168.2.x.
3. Automatic Connection (Auto-Mesh)
Once the setup is complete, the two QHora routers will pair automatically via My Organization:
The Edge device will proactively establish a secure connection to the Hub.
You do not need to configure complex Port Forwarding or firewall rules; QuWAN handles the encrypted tunnel automatically.
Quick Checklist
Same Account: Are both devices logged into the same QNAP ID?
Default Organization: Have both devices joined "My Organization"?
Correct Roles: Is the device with the Public IP set as the Hub?
Unique Segments: Are the LAN IP ranges different at both locations?
Once finished, you will see a green line connecting the two QHora routers on the QuWAN Orchestrator dashboard, indicating that the Site-to-Site VPN has been successfully established.