Docs menu

Back up

Set up a site gateway

A site gateway is a small MoorNest service on a machine at the client's site that keeps backups on the NAS or disk next to it. Servers at the site send their encrypted backups to the gateway over the local network, so restores run at local network speed. The gateway connects out to MoorNest over HTTPS, so nothing needs to be opened in the client's firewall.

When you need one

You need a site gateway to back up to a NAS or local disk at the client's site. You do not need one for MoorNest Cloud or an S3 bucket. One gateway serves one backup folder; for another NAS, add another gateway.

Requirements

  • A machine at the client's site that stays on and sits on the same network as the servers you back up.
  • Linux (recommended), with the NAS share mounted. Or Windows, with a local disk or a NAS volume attached over iSCSI for backups; mapped network drives do not work for a service.
  • Root (through sudo) on Linux, or an administrator PowerShell on Windows.
  • Outbound HTTPS from the gateway machine to app.moornest.com. If it uses a proxy, set HTTPS_PROXY in the shell you run setup from; setup passes it on to the service.
  • The servers you back up must reach the gateway's LAN address. Setup suggests the machine's private address on port 9443.
  • The Administrator role in MoorNest, with your authenticator app set up.
  • NAS storage included in your subscription.

Step 1: download the gateway

  1. In the console, go to Settings > Storage. Under Site gateways, click Add site gateway. (Add server > Site gateway for a NAS opens the same page.)
  2. Under Where will the gateway run?, choose Linux or Windows and click Continue.
  3. Click Download zip.

The zip holds the gateway program and the address of your workspace. Nothing secret is in it.

Step 2: run setup on the gateway machine

Copy the zip to the gateway machine and unzip it. Then run setup from the unzipped folder.

On Linux:

sudo ./moornest-gateway setup

On Windows, open PowerShell as administrator (right-click PowerShell, Run as administrator), go to the unzipped folder and run:

.\moornest-gateway.exe setup

Setup asks two questions:

  1. Backup folder: where backups go. On Linux this is normally a folder on the mounted NAS share. On Windows the default is X:\MoorNest\repositories on the fixed disk with the most free space other than the system disk.
  2. LAN address agents will use: the private IP address and port the servers will send backups to, for example 192.168.1.20:9443.

Setup then creates the gateway's own keys on the machine, sends only public details to MoorNest and prints an address, a code and a key fingerprint:

  Open  https://app.moornest.com/activate
  Code  BCDF-GHJK
  Key   <fingerprint>   (the page shows the same)

Leave setup running. It waits for you to approve the code, which works for 10 minutes.

Step 3: approve the gateway in the console

  1. Back in the console, click It shows a code, type the code and click Continue. You can also open the address setup printed, or click Enter a gateway code under Settings > Storage.
  2. Under Check what is asking to join, check the computer name, system, LAN address, backup folder, free space and where the request came from.
  3. Check that the Key fingerprint matches the one setup printed.
  4. Give the gateway a Name in MoorNest and click Approve. Confirm with your password and a fresh code.

Setup receives its registration, installs and starts the gateway service, and exits. The gateway shows Online under Settings > Storage > Site gateways once its service connects.

Step 4: back up to the NAS

The approved gateway is now storage. When you set up a plan, choose it under Where to keep it; it is shown as NAS at the client site, through a site gateway. See Choose what to back up.

Backup folder rules

On Linux:

  • The folder must already exist, so mount the NAS share and create the folder first.
  • It must be writable by the gateway's service account, moornest-gateway. For example: chown moornest-gateway:moornest-gateway /srv/backups. For an NFS or SMB share, set the owner on the NAS or in the mount options (for CIFS: uid=moornest-gateway,gid=moornest-gateway).
  • Use letters, digits and . _ @ + - / only, with no spaces.
  • It cannot be under /home, /root, /tmp, /etc, /usr or other system folders.
  • Setup warns you if the folder is on the machine's own system disk rather than the NAS.

On Windows:

  • Not a drive root, and not in or above C:\Windows, C:\Program Files or MoorNest's own folders.
  • Not a mapped network drive or CD/DVD drive. A NAS volume attached over iSCSI counts as a local disk.
  • A missing folder is created when you agree to it.

On both, the folder needs at least 512 MiB free, which the gateway keeps in reserve.

What setup installs

LinuxWindows
Program/opt/moornest/moornest-gatewayC:\Program Files\MoorNest\moornest-gateway.exe
Gateway settings and keys/etc/moornest-gatewayC:\ProgramData\MoorNest\gateway
Servicemoornest-gateway.service (systemd)MoorNest Site Gateway (MoorNestGateway), LocalSystem, automatic (delayed) start

On Windows, setup also adds one inbound firewall rule, MoorNest Site Gateway, that allows TCP to the gateway's LAN address and port from private network addresses only. If another firewall product blocks that, setup prints the command to run.

How the connection works

  • The gateway keeps a few connections open out to MoorNest. MoorNest uses them to check the gateway and to read backups for checks and restores. TLS runs end to end through them.
  • Servers send backups straight to the gateway over the LAN. Each agent checks the gateway's pinned certificate.
  • Backups are encrypted on each server before they leave it, so the gateway and the NAS only ever hold encrypted blocks.

Check, remove or revoke a gateway

To see the gateway's status on the machine, run sudo /opt/moornest/moornest-gateway status on Linux, or .\moornest-gateway.exe status from the unzipped folder in an administrator PowerShell on Windows.

To revoke a gateway, go to Settings > Storage > Site gateways and click Revoke. Backups to it stop at once, including any running now. Backups already on the NAS stay there. The machine cannot be approved again with the same key; to use it again, run setup there for a new code.

To remove the gateway from the machine, run uninstall the same way as status. It removes the service and program and never touches the backup folder.

Last updated 4 October 2026.

Look