Unifi Remote User VPN setup and firewall rules

Поділитися
Вставка
  • Опубліковано 12 січ 2025

КОМЕНТАРІ • 127

  • @stephenkiser8243
    @stephenkiser8243 2 роки тому +16

    Heads up to anyone on Android 12, they removed L2TP support, and this latest version of Unifi OS only supports L2TP (it does not support IKEv2, which is the only option provided by Android)

    • @KeyBored101
      @KeyBored101 2 роки тому

      Damn, that answers my one of my issues

    • @robhowe8353
      @robhowe8353 2 роки тому +1

      My android vpn says l2tp/ipsec psk, l2tp/ipsec rsa, ipsec xauth psk, ipsec xauth rsa, ipsec hybrid rsa, then the ikev2

    • @Grynjolf
      @Grynjolf 2 роки тому +1

      What is the solution? Can we use an app on Android instead?

    • @kuflik
      @kuflik 2 роки тому

      I got S20fe and L2TP works well.

    • @d.l.1567
      @d.l.1567 2 роки тому +3

      If you're running Android 12 or especially 13, this tutorial does not apply. L2TP is no longer supported.

  • @jasonax1523
    @jasonax1523 17 днів тому

    Thank you! I was missing one step and your walkthrough helped me reconnect!

  • @ChrisC-Pi
    @ChrisC-Pi 11 місяців тому

    Amazing, finally a tutorial that I was able to follow and it actually worked first time exactly as you showed. 😀

  • @benjaminc.m.9873
    @benjaminc.m.9873 10 місяців тому +2

    Trying to map a SMB drive from my Windows Server so I can access through my VPN. No one has a clear answer out there on how to accomplish this. I can’t see devices and mapped drives on the LAN when connected through VPN. It would be nice if Ubiquiti built in a simple function to turn on that would “bridge” the LAN and VPN subnets together!

  • @thigbe9619
    @thigbe9619 Рік тому

    Thank you so much Mac. You helped me diagnose and fix a connection problem we were having. Getting an error when connecting to the VPN. Had to enable the "Require Strong Authentication" as discussed in your video. Wahhoooo!

  • @peteryates308
    @peteryates308 Рік тому

    This video helped me configure mine, thank you! Some of Unifi's UI is a bit cryptic.

  • @fletchowns
    @fletchowns 2 роки тому +11

    How come the "Block VPN to networks" firewall rule was created as LAN Out and not as LAN In?

    • @JacksonCampbell
      @JacksonCampbell Рік тому

      Good question.

    • @woswasdenni1914
      @woswasdenni1914 17 днів тому

      because you are ON tghat interface, imagine the vpn is connected with a cable on the lan port, so you are already on that interface now you wanna go somwhere else
      like not lan. in would be blocking traffic to that interface, so you can block all other infaces from accessing something on lan by the lan in rule, or you only block lets say guest on the guest out rule

  • @thigbe9619
    @thigbe9619 Рік тому

    Thanks!

  • @Anewtube4you
    @Anewtube4you 2 роки тому +1

    If I'm using DDNS to get a domain name that links back to my home's current external IP, do I just set up the iPhone VPN client to point to this domain? Just a home gamer here, not sure if FQDN = my DDNS domain. My hope is that when my ISP updates my external IP address it won't require me to go back into the iPhone and change the VPN settings to a new server/public IP address.

  • @piranha32
    @piranha32 2 роки тому +3

    Another issue I can't find solution for is restricting access to networks on per user (or user group) basis. Ubiquiti markets UDMP as a solution for small and medium business, and this is functionality which is crucial for proper implementation of remote work.

    • @showstopper81
      @showstopper81 2 роки тому

      Did you ever manage to resolve this?

    • @piranha32
      @piranha32 2 роки тому

      @@showstopper81 Not yet. Probably I need to wait until my UDMP receives a Firmware update with Wireguard built in (already available in UDMP SE).

  • @AceBoy2099
    @AceBoy2099 Рік тому

    I'd appreciate a video on how to make a port use a vpn out (in my case nord) so I can plug the port from my pc into it and it would be covered by the vpn and no need for software on the pc to messup other settings like it has done before.

  • @joshuaimholz3890
    @joshuaimholz3890 2 роки тому +1

    Are you supposed to be able to see active VPN client connections on the controllers client devices section?

  • @bassbacke
    @bassbacke 2 роки тому +1

    Have you tried blocking the gateway addresses as destination and VPN as source on the IN interfaces?

  • @Platoface
    @Platoface 2 роки тому

    Thank you for the help. I have a TrueNAS server I am using to back up my pics daily from my ipad and phone and still wanted access to them after deleting them off my mobile devices.

  • @ventureon_it
    @ventureon_it Рік тому +1

    Any word on if the gateway issue has been solved?

  • @fordsrmaster
    @fordsrmaster 8 місяців тому

    I can ping everything on my home network through my Open VPN connection, except for my Synology NAS. It seems to be a Synology issue. Would you happen to know off-hand what setting needs to be changed in the Synology so that I can connect to it from a different VLAN?

  • @ChristopherNealBUSHIDO49ERS
    @ChristopherNealBUSHIDO49ERS 2 роки тому

    This is a GREAT video! THANK YOU!!!

  • @philippebezoteaux
    @philippebezoteaux Рік тому

    Great vidéo which I used to secure my UID One-Click VPN users. Still trying to block gateways from VPN users, you mentioned that UniFi needed to fill the gap on that. As it been done ? How to block those gateways ?

  • @curiousurick
    @curiousurick Рік тому

    I have a sonicwall but I’m managing Unifi through the application on my server and using Unifi APs. What public IP address should I be using? The one for the sonicwall or should I be making my server host public through port forwarding?
    I tried the network’s public IP address but that didn’t work and I’m nervous to make the entire host available with a public IP address.

  • @Tuskieee
    @Tuskieee 2 роки тому

    I assume you need to enable your radius server also? Mine isnt enabled by default.

  • @JCS707
    @JCS707 3 місяці тому

    Even by default my apple device does not want to talk to other devices on the vpn lan network

  • @OzDeaDMeaT
    @OzDeaDMeaT 2 роки тому

    Would love a tutorial on this without using a phone. Perhaps a Windows 10 or 11 laptop? I also cant ping anything on any of my other VLAN's, but I want to be able to connect to them. Any ideas?

  • @adammaik
    @adammaik 6 місяців тому

    No changes for blocking gateway pinging?

  • @rex0522
    @rex0522 2 роки тому +1

    Hi, great thanks for your shared video first, I follow all firewall rule setup in my new UDM SE and work fine. only after I setup the block VPN to network rule(RFC1918 to RFC1918) , it turns out default network cannot connect HP AIO printer on IoT VLAN, would it make sense to setup the block rule (VPN user to RFC1918)? I did it and HP AIO printer work fine now.

  • @simonemastellonephotography
    @simonemastellonephotography 2 роки тому

    Hi, stied to install following you guide, all is working however once is set up the rules on lan out i lost connectivity to the app under reverse proxy on my server , how can i solve

  • @miguelfmsmac
    @miguelfmsmac 5 місяців тому

    Great video. What’s the name of the Ping app on your iPhone. Thanks

  • @DJGeek
    @DJGeek 2 роки тому

    I'm trying to setup ddns for my VPN as I have a dynamic IP address but having issues.

  • @astraldrifter
    @astraldrifter Рік тому

    Please can you show us how to do L2TP VPN from windows server 2022 RRAS server using Ubiquiti please

  • @brunomallmannformulo6271
    @brunomallmannformulo6271 2 роки тому +1

    I have a problem. I can only connect with one vpn l2tp user at a time from the same remote ip. Does anyone know how to fix?

  • @chadsteffen9715
    @chadsteffen9715 2 роки тому +2

    What if you don’t have a static public IP. What would be the best solution?

  • @TheDmankl
    @TheDmankl 2 роки тому

    I have not been able to get the USG3 to do VPN, I have followed the guides ... it just doesnt connect. Is this normal or should I try and get UDM pro for it to work?

  • @online_now6834
    @online_now6834 2 роки тому +1

    can connect from my iphone, cannot connect from my mac. If I connect to my iphone on cellular to simulate outside connection I can connect to the vpn but cannot ping anything on LAN

    • @lawyerdch
      @lawyerdch 2 роки тому

      I have a similar issue. My issue is I cannot ping any LANs from home wifi, but am successful from cell service.

  • @waynenocton
    @waynenocton 2 роки тому

    I followed along your video while looking at my setup but I could only ping the router no matter what I did. I tried several firewall rules and nothing helped, but then I wondered if it was the address that caused my issue. So, most of the networks are 192.168.x.x but I set one network to 10.0.4.x because there was software that had things setup with that address, I did it to stop issues, but it seems like I created issues instead. Is there a firewall rule I can add to allow this crossing of IP addresses? I will definitely be using your donate button if I can get this resolved!

  • @josel82
    @josel82 2 роки тому

    Very useful video. Thanks

  • @robhowe8353
    @robhowe8353 2 роки тому

    I'm a noob, but I hope I can get some advice. I locked down my vlans from each other and all the gateways and udm like you advised in the firewall vids, and locked all my lan and vlan traffic to specific ports and disabled the rest, so now you have to log in on the land port only to get into my udm pro. I still want to use my unifi android app though, and cant because its locked out of the lan. Is it advisable to set up a remote VPN so my phone can access the udm pro for remote administrator with the app? I'm guessing this is a security no no.

  • @ke4rcf
    @ke4rcf Рік тому +2

    Good video. One item that was not covered was how you allow multiple VPN connections at the same time. I have the exact same set up without the firewall restrictions and when the second VPN connection hits it will kick the first one off. Both Windows machines. This seems to be an open issue if you research the forums. How are you getting around this limitation?

  • @guillaumeb.4451
    @guillaumeb.4451 2 роки тому

    Hi Guys, has someone tried to connect to the VPN with an android based phone, not working for me. I wonder whether the weak cyper option is not necessary for this.

  • @kirilblagov7715
    @kirilblagov7715 Рік тому

    Can you do split VNP on udm pro

  • @bytelander
    @bytelander 2 роки тому

    Hello,
    I am trying to create a firewall rule on a UDM SE to prevent the remote network (Site-to-Site OpenVPN) from accessing the IP addresses of the gateway (UDM SE). Unfortunately I do not succeed.

  • @raine-works
    @raine-works 2 роки тому

    How does this work on mobile networks that use ipv6 addresses?

  • @lawdawg1942
    @lawdawg1942 2 роки тому

    Just ran into this today, buddies UDMP VPN connected and you can ping AP's etc but RDP would not work. IPS was set to high and it blocked it. I had to put it on low before RDP could hit the computer. Also can't ping local computers but apparently thats a windows firewall thing?

    • @TheDmankl
      @TheDmankl 2 роки тому

      Sounds like one of the things that are blocked would either be the port or protocol for RDP when you increase the IPS.you can set a firewall rule for that

  • @haydenbutler1409
    @haydenbutler1409 11 місяців тому

    Could you do an updated one?

  • @brwyatt
    @brwyatt 6 місяців тому

    Every VPN/Firewall tutorial (from everyone) always shows how to block the VPN network(s) from accessing resources on the LAN (using LAN Out). I cannot seem to find any information for blocking traffic from a local network *TO* a VPN network (other than blocking returning packets via LAN Out), and I've been unsuccessful in trying to get it to work.

  • @amilcarvieirapt
    @amilcarvieirapt Рік тому

    VPN Access, once connected I cant access my local network, only Unifi SE

  • @JS-jc5mb
    @JS-jc5mb Рік тому

    do you have to bridge the router?

  • @JasonsLabVideos
    @JasonsLabVideos 2 роки тому

    Can't you drop ICMP on the gateways Cody ? Could you create a rule to block the PORT for the gateway ip's that direct to the log in page ?

  • @spacemanwho
    @spacemanwho Рік тому

    Thanks for this. Folks, what do Name server1 and 2 relate to?

    • @MactelecomNetworks
      @MactelecomNetworks  Рік тому +1

      Your dns servers

    • @spacemanwho
      @spacemanwho Рік тому

      @@MactelecomNetworks I used your video to setup a vpn connection back in from another site and even locked it down to only reach the ip address for my NVR. Stay awesome dude. In theory once I have the remote site modem/router configured the cameras on that site should be able to talk about to my NVR at home. Ping test worked from the iPhones vpns connection.

  • @viniciuspinheir0
    @viniciuspinheir0 2 роки тому

    Can you make a video with IPv6?

  • @maniejv86
    @maniejv86 Рік тому

    When I access my noip account info, all I see is my basic info email address. I do not see my username and password. Do I have to upgrade my account to obtain a username and password?

  • @lawyerdch
    @lawyerdch 2 роки тому

    Excellent video. I followed all your steps and when I ping from my phone while connected to t-mobile, it works like a charm. However, when I ping from my phone (or home computer) while on my home network (also a UniFi dream machine set up), I get timeouts to all office networks even though I’m connected. Help? Anyone?

  • @thepresi2
    @thepresi2 2 роки тому

    Is the massive issue of VPN users being able to access to the gateways being fixed? It seems not, right?

  • @Harpdog440
    @Harpdog440 Рік тому

    In the first firewall rule to block, you used RFC1918 for both Source and Destination. Was that a mistake?

    • @NETWizzJbirk
      @NETWizzJbirk Рік тому +1

      Obviously a mistake or he has no idea what he is doing because he blocked all private IP traffic at least that is Lan out.

  • @Lonestar101
    @Lonestar101 2 роки тому

    Everything makes sense, except your rushed over the IP Port Groups (what you call RFC1918). Where do those IP address come from?

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому

      Making an updated firewall video this week. But RFC1918 if request for comments 1918 its a white paper based on all the private IPv4 addresses

  • @palles1972
    @palles1972 2 роки тому

    There was an error deleting the VPN network. Object is referenced by User

  • @eloyl2033
    @eloyl2033 2 роки тому

    Any good options to set this up for an android phone? Unfortunately android does not support L2TP anymore.

    • @alexeichekovic5923
      @alexeichekovic5923 2 роки тому

      I have a Samsung A71 and it works :)

    • @eloyl2033
      @eloyl2033 2 роки тому +1

      @@alexeichekovic5923 Android 12 removed some of the protocols, L2TP is not an option anymore.

    • @randylane3079
      @randylane3079 2 роки тому

      L2TP/IPSec PSK type works on a Samsung Galaxy S10

  • @bhenriquealves
    @bhenriquealves 2 роки тому

    Would be great to have fixed ip address to VPN users.

  • @boudewijndejong9134
    @boudewijndejong9134 2 роки тому

    Do the firewall rules also apply when using the UID VPN option?

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому +1

      This I’m unsure of I need to load UID again but I willl do in the next week and let you know

    • @boudewijndejong9134
      @boudewijndejong9134 2 роки тому

      @@MactelecomNetworks that would be great as the one click VPN is very nice

  • @thenickrodriquez
    @thenickrodriquez 2 роки тому

    I get the iphone to work with no issues, but my Macbook I have no luck with.

  • @a.klasen570
    @a.klasen570 2 роки тому

    I get an error when I try to connect to my VPN on windows, this is my error:
    a connection to the remote computer cannot be established.you might need to change the setting for this connection

  • @e281tangy
    @e281tangy 2 роки тому

    what's that PING app?

  • @itsuzairkhan
    @itsuzairkhan 2 роки тому

    It's frustrating that the firewall rules allow/block by network and not by user. What if I have a VPN user who want to give access to my NAS but another user who I don't. What if I have a user who I want to be able to rdp into a specific machine but another user who I don't want to. I think Ubiquiti needs to allow setting static IPs for VPN users so that the firewall can be configure for source and destination IPs rather then for the whole VPN Network.

    • @alspcrepair
      @alspcrepair 2 роки тому

      thats the same question i have. did u ever figure out how to give each user there own vpn access ?

  • @jfkastner
    @jfkastner 2 роки тому +1

    Can you just move the https port # for the UDM login page to some secret non-standard number? That would 'hide' that page from a regular user. Good video, thank you!

  • @sujaybhakat2548
    @sujaybhakat2548 2 роки тому

    Netgate 7100 1u rack vs udm pro plz

  • @fin3125
    @fin3125 2 роки тому

    Android is not the same and seems to have issues for me.

  • @alexeichekovic5923
    @alexeichekovic5923 2 роки тому +1

    I've noticed this issue few month ago. It is possible to ping GW and also access to the WEBUI of the GW ... ! I don't understand why Unifi don't patch this critical issue :/

    • @curtispavlovec
      @curtispavlovec 2 роки тому

      I think it’s because most people aren’t using vpn on the UniFi devices directly since they aren’t doing WireGuard. Supposedly they are working on it but wouldn’t hold my breath. Having L2TP as your VPN these days is…well, not good. That’s all I’m going to say.

    • @alexeichekovic5923
      @alexeichekovic5923 2 роки тому +2

      @@curtispavlovec I totally agree ! But it is very strange that Unifi don't make a better VPN. It's not a poor chinese network brand..

    • @TheDmankl
      @TheDmankl 2 роки тому

      @@alexeichekovic5923 I would love them to improve their VPN, I have a small network with a USG not UDM and I have been unable to get a working VPN setup. I have had to setup a small vm with PiVPN.

  • @derFuzzy
    @derFuzzy 2 роки тому +1

    This VPN LT2P or whatever is NOT working any longer on Win 11!

    • @lawdawg1942
      @lawdawg1942 2 роки тому

      Windows 10 had a "optional" update to fix the VPN issue they created in an update. Check into that.

  • @xVertigo101
    @xVertigo101 2 роки тому

    I tried to set this up but for some reason my remote clients are ignoring the two simple lan out rules.
    Rules are Block RFC1918 and Allow VPN to 192.168.4.17.
    Allow VPN rule is above the RFC1918.
    VPN is on the 192.168.5.0/24 subnet.
    Firmware for UDM-Pro is 1.12.33

  • @Revoc
    @Revoc 2 роки тому

    Anyone get OSX working. Can connect to VPN and get the WAN IP but unable to ping or connect to local devices.

  • @abod1782
    @abod1782 2 роки тому

    Every time I create a user , it disappears after restarting the UDM.

    • @abod1782
      @abod1782 2 роки тому

      Something is wrong with the latest release.

  • @patleonard8079
    @patleonard8079 2 роки тому +1

    Cody, I’m pretty sure you can block the gateways. I made a group including the IP address of the gateways, then blocked the network to those. I used it to block IOT devices from getting to my regular network. I’m almost positive that Chris from Crosstalk solutions did a video about it.

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому +2

      You can block networks from reaching your gateway that’s true but when connected through the vpn it doesn’t alllow it. I’ll give it a try again but don’t believe it works

    • @patleonard8079
      @patleonard8079 2 роки тому +1

      @@MactelecomNetworks I haven’t tried it through a VPN. Although I was under the impression that the UDM with firewall rules just assumes it another VLAN. That is a valid point that it would not allow it to work with a VPN. Thanks for the feedback

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому +4

      @@patleonard8079 Ya thats how it should work ive tired under each place WAN_IN, LAN_Out eveyrthing and nothing blocks. hopefully it gets updated

    • @javiercamacho1673
      @javiercamacho1673 2 роки тому

      @@MactelecomNetworks The firewall rule "Block VPN to Networks" on LAN_OUT will also affects all your UDM Site-to-Site VPNs, so, for somebody using S2S combined with VPN Client-to-Site, add another firewall rule on top to allow all your S2S VPNs as well.

    • @Thermonator621
      @Thermonator621 Рік тому

      Just wondering how can you block the gateway if you are connected through VPN to that gateway?

  • @mathieuleclerc4136
    @mathieuleclerc4136 2 роки тому

    I guess the modem should be on bridge mode....

  • @davidfrey8493
    @davidfrey8493 2 роки тому +2

    the RFC1918 IP group is really unclear to me on what it is doing, is that every vlan you have on your UDM?
    I found the answer in another video ua-cam.com/video/tS4-ClQuo3g/v-deo.html

    • @matthewlswanson
      @matthewlswanson 10 місяців тому

      Video does not exist anymore :( at least with that link

  • @ronm6585
    @ronm6585 2 роки тому

    Thanks

  • @kylejoel87
    @kylejoel87 2 роки тому

    The protocol is outdated and unifi needs to move with the times with there VPN protocol. They need to added lime Wireguard, I hate to day this even OpenVPN at the least but defo Wireguard.

    • @lawdawg1942
      @lawdawg1942 2 роки тому

      They have UID in early access. That's probably their solution.

  • @sidpatel77
    @sidpatel77 10 місяців тому

    why is this easier than nordlayer....

  • @21Lettere
    @21Lettere 2 роки тому

    L2TP is an outdated and *insecure* VPN protocol!

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому

      It is but the only options right now. Wireguard is coming

    • @TheDmankl
      @TheDmankl 2 роки тому

      @@MactelecomNetworks Do you know when this might be happening?

  • @wmw8453
    @wmw8453 2 роки тому

    I WISH I could see your screenshots clearly. Ruined an otherwise excellent video.

    • @MactelecomNetworks
      @MactelecomNetworks  2 роки тому

      What screenshots are you referring to? I just watched the whole video again and everything is clean. Are you watching on a phone?

  • @thematrix1999
    @thematrix1999 8 місяців тому

    Make the rule to Lan Local destinations the gateway on every vland and the gateway for the vpn drop only port 80, 443,22