Enterprise AV Home WiFi Mobile Wifi Support Shop Deals
Insight's Business VPN service allows NETGEAR business routers to securely connect over a virtual private network (VPN) from off-site branches or employee home offices to a central office. For more information, see What is Insight Business VPN?.
Before you can set up your Insight Business VPN service, you must first complete the following prerequisites:

The following diagram shows a typical Insight Business VPN deployment:

Insight Business VPN multiple office diagram

To set up your Insight Business VPN service:

  1. Log in to your Insight account.
  2. If you have an Insight Pro account, select an organization.
  3. Select the location where your central office is located.
  4. Select Router/VPN > VPN Settings > +.
  5. In the Group Name field, enter a name for your business VPN.
  6. In the Description field, enter a description of your business VPN.
  7. In the Maximum Transmission Unit (MTU) field, enter a limit on the MTU size for the router's business VPN connection.

    The MTU sets the transmission unit size that your business router can receive and transmit.

  8. Click the Domain Names through VPN slider button, if internal domain names are accessible through the VPN.
  9. In the Domain Name field, enter a domain name and click Next.

    The Add Central Router page displays.

  10. Click Add Central Router.

    The Central Router page displays.

  11. In the Select Location section, select the network location of your central office.
  12. In the Select Router section, select the central router from your main office.

    After you select a router to be the central router, Insight automatically populates the Router IP Address and Router IP Subnet fields with the selected router's information.

    Caution: If you specify a different IP address and IP subnet, Insight changes the central router’s LAN IP to the new value when you save the settings.
  13. Select the VLAN Profile button.

    A list of VLANs that are enabled on the central router displays.

  14. In the VLAN section, select the VLAN that is associated with the central router.
  15. In the VPN Networks field, enter the VPN network that the central router's Internet port is connected to.

    The VPN networks are the local networks at the main office that are accessible by the central router's WAN port.

  16. Click Save.

    The Router page displays.

  17. Click Add New Remote Router.

    The Remote Router window displays.

  18. In the Select Location section, select the location of your branch or employee home office.
  19. In the Select Router section, select a remote router.

    After you select a remote router, Insight automatically populates the Router IP Address and Router IP Subnet fields with the selected router's information.

  20. In the VPN Credits section, select an available business VPN credit to allocate to the remote router.
  21. Click the VLAN Profile slider button.

    A list of VLANs that are enabled on the remote router displays.

  22. In the VLAN section, select a VLAN for the remote router.
  23. In the Router Mode section, select the Employee Home or Branch Office.
  24. (Optional) To enable router isolation on your employee home router, click the Router Isolation slider button.

    The router isolation feature is only available for employee home routers. For more information, see What is Insight Business VPN router isolation?.

  25. Click Save > Next.

    The Wireless Settings page displays.

  26. (Optional) To enable WiFi client access to the Business VPN service, select the VPN Wireless Network button.
    1. In the Security section, select security the type WPA2-PSK for the Business VPN SSID.
    2. Enter an SSID name and password for the Business VPN service.
  27. Click Next.

    The Access Control page displays.

  28. (Optional) To add an access control list (ACL), in the Access Control section, select the + icon.

    The Add New Device window displays.

    An ACL adds a layer of security to your wireless network. For more information, see What are Access Control Lists (ACLs) and how do they work?.

    1. In the Device Name field, enter the name of the device.
    2. In the MAC Address field, enter the MAC address of the device.
    3. In the Rules field, select Allow or Deny.
    4. In the Select Router field, select a router to apply the ACL to.
    5. Click Save.
  29. Click Next.

    Your Insight Business VPN service is set up.

Last Updated:07/07/2025 | Article ID: 000063725

This article applies to:

Recently Viewed Articles

    Read this article in another language:

    • United States (English)
    • 日本 (日本語)

    Read this article in another language:

    Our team is here to help!

    Phone
    Chat
    Email