Two sites, one Tally or file server, and a “just put AnyDesk on everything” habit. That works until a laptop is stolen or a contractor still has last year’s password. For Baddi–Nalagarh pairs we prefer a site-to-site or user VPN with a short written list of what is allowed across.

Name the traffic

Accounts to the Tally server. Stores to one share. Printers only if someone actually prints from the other town. If the list is “the whole LAN”, you have not designed a VPN — you have joined two offices into one noisy network.

Static IPs and a spare path

Record both ISP routers, WAN IPs (or DDNS names) and who holds the admin login. When one fibre dies, people should know whether the VPN will come back on 4G failover or whether Tally is local-only until the line returns.

Users, not a shared PSK in a WhatsApp group

Site-to-site tunnels use a key on the routers. Staff who travel should get their own VPN user that you can disable. MFA on that user is worth the extra minute at login.

Test a file, not a ping

Green lights on the router are not enough. Open the share, post one Tally voucher, print if that was the point. Then write the result on the same one-pager as the office network checklist.

Need both sites joined? See Networking & VPN or send a note via Contact.