Unifi Remote User VPN setup and firewall rules

preview_player
Показать описание
In this video we setup a remote user VPN in Unifi network controller 7.0.23 we also create firewall rules to block the VPN users from accessing networks we do not want them to go

------------------------------------------------------------------------------------
▶Ubiquiti affiliate link:

▶ Hire us on our website

▶Join our discord server:

▶Contact me on email:

------------------------------------------------------------------------------------
Affiliates I use:

▶ Hostifi Unifi and UISP Cloud Hosting

▶ VOIP.MS

▶Canadian Amazon Store front:

▶USA Amazon store front:

------------------------------------------------------------------------------------
▶ Find us on social media:

▶ Instagram:

▶ Facebook:

▶ Twitter:

▶ TikTok:

▶ Linkedin:

Intro 0:00
Creating the Remote user VPN 1:26
Adding VPN to iphone 3:23
VPN Firewall rules 4:34
Final thoughts 7:34
Рекомендации по теме
Комментарии
Автор

Heads up to anyone on Android 12, they removed L2TP support, and this latest version of Unifi OS only supports L2TP (it does not support IKEv2, which is the only option provided by Android)

stephenkiser
Автор

Thank you! I was missing one step and your walkthrough helped me reconnect!

jasonax
Автор

Amazing, finally a tutorial that I was able to follow and it actually worked first time exactly as you showed. 😀

ChrisC-Pi
Автор

How come the "Block VPN to networks" firewall rule was created as LAN Out and not as LAN In?

fletchowns
Автор

Thank you so much Mac. You helped me diagnose and fix a connection problem we were having. Getting an error when connecting to the VPN. Had to enable the "Require Strong Authentication" as discussed in your video. Wahhoooo!

thigbe
Автор

Trying to map a SMB drive from my Windows Server so I can access through my VPN. No one has a clear answer out there on how to accomplish this. I can’t see devices and mapped drives on the LAN when connected through VPN. It would be nice if Ubiquiti built in a simple function to turn on that would “bridge” the LAN and VPN subnets together!

benjaminc.m.
Автор

This video helped me configure mine, thank you! Some of Unifi's UI is a bit cryptic.

peteryates
Автор

Are you supposed to be able to see active VPN client connections on the controllers client devices section?

joshuaimholz
Автор

If I'm using DDNS to get a domain name that links back to my home's current external IP, do I just set up the iPhone VPN client to point to this domain? Just a home gamer here, not sure if FQDN = my DDNS domain. My hope is that when my ISP updates my external IP address it won't require me to go back into the iPhone and change the VPN settings to a new server/public IP address.

Anewtubeyou
Автор

Any word on if the gateway issue has been solved?

ventureon_it
Автор

I can ping everything on my home network through my Open VPN connection, except for my Synology NAS. It seems to be a Synology issue. Would you happen to know off-hand what setting needs to be changed in the Synology so that I can connect to it from a different VLAN?

fordsrmaster
Автор

I have a problem. I can only connect with one vpn l2tp user at a time from the same remote ip. Does anyone know how to fix?

brunomallmannformulo
Автор

I'm trying to setup ddns for my VPN as I have a dynamic IP address but having issues.

DJGeek
Автор

Have you tried blocking the gateway addresses as destination and VPN as source on the IN interfaces?

bassbacke
Автор

can connect from my iphone, cannot connect from my mac. If I connect to my iphone on cellular to simulate outside connection I can connect to the vpn but cannot ping anything on LAN

online_now
Автор

No changes for blocking gateway pinging?

adammaik
Автор

I have a sonicwall but I’m managing Unifi through the application on my server and using Unifi APs. What public IP address should I be using? The one for the sonicwall or should I be making my server host public through port forwarding?

I tried the network’s public IP address but that didn’t work and I’m nervous to make the entire host available with a public IP address.

curiousurick
Автор

What if you don’t have a static public IP. What would be the best solution?

chadsteffen
Автор

I'd appreciate a video on how to make a port use a vpn out (in my case nord) so I can plug the port from my pc into it and it would be covered by the vpn and no need for software on the pc to messup other settings like it has done before.

AceBoy
Автор

Even by default my apple device does not want to talk to other devices on the vpn lan network

JCS