TABLE OF CONTENTS
Configure VPN Server on UniFi Network
Most recent UniFi Cloud Keys and Dream Machines will support at least one type of VPN. This guide will cover all protocols supported by UniFi OS besides PPTP because this protocol is grossly insecure to such a degree that you might as well start opening ports.
Configure VPN Server in UniFi OS
- Navigate to VPN server configuration within UniFi OS by following: Network -> Settings -> VPN -> VPN Server -> Create New
- Determine VPN Protocol to Use (Currently Supported in UniFi OS: L2TP, OpenVPN & WireGuard)
- Follow Appropriate Subsequent Steps
Configure VPN Client Device
WireGuard
- WINDOWS - Install WireGuard Installer through Internet Browser. MacOS - Install WireGuard through the App Store
- In UniFi - Click 'Add Clients' after selecting WireGuard as the VPN Protocol of choice.
- Download the Configuration File.*NOTE* unique user per device is required
- Make sure to ADD and APPLY CHANGES for the created client
- In WireGuard - Select Import tunnel(s) from file and select the downloaded configuration file from UniFi
- To connect to the remote network, click activate on the designated tunnel.
- This configuration can also be accomplished with specific authentication details via the 'Manual' page selectable when adding a new client but this is ill advised as significant security concerns are presented.
OpenVPN
L2TP
- WINDOWS
- MacOS
- In UniFi - Create a New User
- On MacOS system open System Settings -> VPN -> Add VPN Configuration -> L2TP over IPSec...
- Create Proper Display Name (just to identify the right VPN)
- Server Address on client Mac is the same as the Server Address IP Address stated in the UniFi VPN server. *NOTE* this must be a static IP if a DNS is not made
- Account Name = Username
- Set user authentication to "password" and put the corresponding password of the username
- Set the Machine authentication to "Shared secret" and type in the Pre-Shared Key
- Switch it on and wait for connection.
Troubleshooting
WireGuard
Q. Client Devices are not saving on the UniFi VPN
A. Be sure to select "Apply Changes" at the bottom left after adding a client.
Q. Cannot connect to remote network after creating WireGuard tunnel
A. Make sure client was successfully added to the VPN server, if it was not you have to get a new configuration file.
A2. The client's system may require a restart. NOT the UniFi VPN Server.
Q. Not sure which VPN tunnel to select / Connecting to the wrong VPN Server
A. If you have multiple tunnels, be sure you are selecting the correct tunnel. This can be identified through matching the endpoint found in WireGuard's tunnel configuration to the UniFi VPN server IP Address Be sure to select "Apply Changes" at the bottom left after adding a client.
OpenVPN
L2TP
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article