No video

The Weird UniFi Wireguard & OpenVPN Remote User Options in UnIFi Network Application 7.2.92

  Рет қаралды 33,539

Lawrence Systems

Lawrence Systems

Күн бұрын

Пікірлер: 89
@KyleRassweiler
@KyleRassweiler 2 жыл бұрын
Na I'm watching after investing into their ecosystem...... now I'm stuck.
@freman
@freman 2 жыл бұрын
The one time in my life I'm like "I'm going to use a purpose built device" boy do I regret that, I can't do the simple things I used to do
@spoils8179
@spoils8179 2 жыл бұрын
@@freman Simple things like what? I'm looking to grab Unifi stuff for my home but I don't want to go anywhere else because the UI is so nice and it looks like it looks so nice in a rack.
@HaemonAK
@HaemonAK Жыл бұрын
Well, good for you since the new 3.x firmware added the actual full Wireguard.
@celliott113
@celliott113 Жыл бұрын
As of UniFi OS UDM Pro 3.0.19 (UniFi Network 7.4.149) it now natively supports both WireGuard and OpenVPN as well as L2TP. Go to Settings -> Teleport & VPN -> VPN Server (Create New)
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
Yeah, they are finally doing things like a normal firewall.
@renehoehle
@renehoehle 11 ай бұрын
@@LAWRENCESYSTEMSI try at the moment a UDM-Pro as Firewall... but hmm... The Domain Filter isn't working and so on. The concept with the In and Out is very strange and that you have all open as default is strange as well.
@Techieguy93
@Techieguy93 2 жыл бұрын
Excellent Video, Tom! I ran into the L2TP issue with 2 users working from home on the same network (husband and wife), and it was maddening to figure out why it kept dropping out when connecting back to a UDMP! I finally figured out why, and then had to come up with a solution. The other note about it being blocked or having issues with a double NAT was also incredibly helpful. I used to have an OpenVPN set up on a Synology NAS for a client, but then moved them to the VPN in their UDM. Never had an issue with OpenVPN, but they have had the L2TP VPN tunnel blocked quite a few times recently. Will investigate the best config to move away from L2TP on the UDM/UDMP/UDMPSE. Thank you, Tom!
@joelsaindon1314
@joelsaindon1314 2 жыл бұрын
Doing it the way they're doing it is so dumb. It's like a network engineer wasn't even involved in the decision. Another reason why their routers and "firewalls" don't have a place in enterprise or even SMBs
@cdoublejj
@cdoublejj 2 жыл бұрын
they may have issues with turn over and getting good engineers to program for them due to thier issues and scandals
@MactelecomNetworks
@MactelecomNetworks 2 жыл бұрын
Great video. MacOS does have a client it’s just the wifiman app you need for teleport. Still no windows client
@dirkbecker2066
@dirkbecker2066 Жыл бұрын
They have added in UniFi Network Application 7.3.69 Add Wireguard VPN server support, requires UniFi OS 3.0 or newer. and Add VPN Client Routing, requires UniFi OS 3.0 or newer. also Allow adding multiple VPN Clients, requires UniFi OS 3.0 or newer.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
Perhaps doing these videos complaining about the weird way they do things is working. 😆
@YeOldeTraveller
@YeOldeTraveller 2 жыл бұрын
Thanks for the information. The more I learn about Ubiquiti, the happier I am that I abandoned them years ago.
@sammccollum2985
@sammccollum2985 2 жыл бұрын
Mikrotik it is, then! This is exactly why I quit using or recommending Ubiquiti. It's ridiculous to need to use a cloud service for any of the features to work and I don't want to deal with proprietary extensions or implementations. It just makes everything too complicated.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
I prefer pfsense ense firewalls
@garrettslade
@garrettslade 2 жыл бұрын
Teleport I thought would be easy but disconnects every few seconds on cell. Hopefully someone figures out this bug. Crosstalk did a teleport video yesterday and tons of issues with teleport disconnecting.
@Timi7007
@Timi7007 2 жыл бұрын
I'm just running Wireguard on a linux box behind my UDM, works great.
@kolt9307
@kolt9307 2 жыл бұрын
Same, super easy and don't have to mess around with their poor excuse of a VPN
@nster3
@nster3 2 жыл бұрын
oh that's possible? That's awesome, maybe I will start dabbing into VPNs then!
@Timi7007
@Timi7007 2 жыл бұрын
@@nster3 Easiest way to get started is probably using PiVPN. Works on most Linux installs and configuration is simpler than plain Wireguard.
@Crazy--Clown
@Crazy--Clown 2 жыл бұрын
@Timi Yep that's the smart way of doing it.
@Qosmio1955
@Qosmio1955 2 жыл бұрын
Similar. I have a NUC which runs Proxmox. Proxmox hosts Home Assistant, Pi-Hole, Unifi Controller, a Windows 10 VM and Shinobi security camera software either as VMs or containers. I also run Plex on my separate TrueNAS Core box. Home Assistant has a Wireguard add-on which is super simple to configure. I can VPN into any VM, container, or TrueNAS or Plex using Wireguard. Very easy to set up.
@mammothkiwi
@mammothkiwi Жыл бұрын
Glad I checked this video. I'll be continuing to use Open VPN through Synology until I have access to Unifi Portal via Windows PC as well as mobile
@DavideDavini
@DavideDavini 2 жыл бұрын
Also the UXG Pro doesn’t have Teleport yet. Which is mind boggling for me. Fortunately I don’t use the Ubiquity gear for VPN and I never will apparently.
@hafeezhamama9580
@hafeezhamama9580 2 жыл бұрын
I aspire to be a network engineer one day and I will admit that I jumped the gun replacing all my home networking devices with Ubiquiti gear. But at the end of the day. I understand and accept the limitations and quirks for what I got. They're not enterprise by any means, but they're a big step up from consumer grade gear in my opinion. I'd gladly recommend Ubiquiti to any one and I'd even them to small to medium sized businesses depending on their needs.
@Crazy--Clown
@Crazy--Clown 2 жыл бұрын
Go learn the OSI model would be a good start
@hafeezhamama9580
@hafeezhamama9580 2 жыл бұрын
@@Crazy--Clown already did that. Studying for my ccna right now
@celliott113
@celliott113 Жыл бұрын
Awesome to hear about your aspirations! That's really cool, and yeah I'm in the same boat in the sense that I decided to go the "affordable" route and upgrade my home network and equipment to an all UniFi (Prosumer) setup as some of the other higher grade cloud options require licenses and are stupid expensive. However something to note, although something may advertise/market themselves as "Enterprise" doesn't always hold water. The company I work for and manage their networks is a 100% all Cisco Meraki network. And oh boy, do you pay the stupid price of enterprise grade equipment and licenses but my guy....Is it faaaarrrrr from actually being enterprise ready. There are so many quirks, bugs, limitations, etc. that prevent it from being a true enterprise ready product. With that said, it's still great, easy to set up, manage, etc. But yeah, always do your homework when looking for the next best thing to upgrade your home network or any network for that matter, sometimes you'll get burned by general marketing wank even from big name reputable brands such as Cisco.
@plrpilot
@plrpilot 2 жыл бұрын
I’ve been using the unofficial back door WireGuard installation for a few remote UDMs for about two years. I’ve had zero issues through upgrades. I keep a single l2tp connection available just in case, but I’ve not had to use it, yet. I just have a hard time trusting their self generated keys. I’d rather generate them all myself and keep them private. I should also note that these UDMs are all residential use machines. For all business uses, I still stick with pfSense.
@cdoublejj
@cdoublejj 2 жыл бұрын
i wonder how that would go with a USG i've heard it works with the same config tweaks as well
@plrpilot
@plrpilot 2 жыл бұрын
I agree that it should, but I’ve only tested the setup on UDM and UDM-Pros. I have a few USG and G2’s that I manage, but they are on systems with pfSense firewalls and do not perform any firewall functions.
@cdoublejj
@cdoublejj 2 жыл бұрын
@@plrpilot the only reason i'll consider the udm pro is for the g4 door bell pro but, if any SMALL poe onvif door bells come out it's game over. i don't like the vendor lock in too much but, it does integrate with unifi but normally i run dd-wrt or untangle. in another 10 years there might be a FOSS network device integration API or something. perhaps i should look at the back door setup. this setup uses starlink and needs either a cgnat tunneling service or phone vpn or wireguard
@plrpilot
@plrpilot 2 жыл бұрын
@@cdoublejj I’m not recommending any hardware. I’m just passing along my specific experience.
@cdoublejj
@cdoublejj 2 жыл бұрын
@@plrpilot oh for sure and thank you. I just like pissing and moaning. Lol
@mrpcakes
@mrpcakes Жыл бұрын
i finally got around to setting up my own domain to be able to use UID .. very cool stuff. 6:41 is exactly what i was looking for especially to upload it to my travel router. might come in handy 🙂
@dalehuitt
@dalehuitt 2 жыл бұрын
Great video as usual. I really wish Ubiquiti/Unifi would get this implementation straight. Unifi has so many great features. I tried to use the Unifi VPN and quickly gave up. In a fraction of the time I had spent trying to get Unifi to work, I had a small router using pfSense. I deployed pfSense for VPN plugged in to my UDM Pro. Works flawlessly. Why can't Unifi get there??
@austinwilson930
@austinwilson930 2 жыл бұрын
I really love most of the unifi equipment but just can't find myself to ever want to install one of their firewall/routers due to the vpn limitations. pfSense is just so easy and gives you so much flexibility.
@s.i.m.c.a
@s.i.m.c.a 2 жыл бұрын
pfSence implements it's no much better, hopefully bare linux terminal do the trick.
@eugenesmirnov252
@eugenesmirnov252 2 жыл бұрын
Another reason to implement L2TP over IPSEC. Both cripples sustains each other. WG and OVPN implementations in Ubiquity it's.. just something. Can't imagine how you may stay polite while talking this.
@wizdude
@wizdude 2 жыл бұрын
An important note - that is documented in their notes - is that the vpn link generation service only works in USA and Canada.
@Lachlan_McDougall
@Lachlan_McDougall 2 жыл бұрын
Worked fine for me in Aus
@travisaugustine7264
@travisaugustine7264 Жыл бұрын
Of course they changed things and for the life of me I can't find where to download the openvpn config file anywhere now. Figures. I don't mind wireguard and I don't need UID to use it but still, I like the idea of having the option.
@bobwong8268
@bobwong8268 2 жыл бұрын
👍👍👍👍👍Dear Tom, Thanks for this very important info; greatly appreciated! Thanks for saving the rest of us from the pains and agongy. A unified solution is NOT well integrated?! All thanks to proprietory vendor lock in; I could feel the pain b/c it could've been me stuck there. If only 1 or 2 devices, I might replace the firmware altogether; then again there need to be a project like "open dd-wrt" tt support that particular device... then again it must worth the effort & time. And it's not really unified again. Now, if I ever go this route, you have given me some heads-up as prep for a more informed decision. All that said, they must also shine in certain ways that is great fit for uses. So, research b4 jumping in. Thanks again for being a great source of knowledge. PS: Just got pfsense & proxmox up & running after going thru multiples of videos from YOU, LLTV, and some others. Yes, the fw is my first device tt marks that beginning of my HomeLab.😊
@nubaus
@nubaus 2 жыл бұрын
What really sucks is that the multitude L2TP issue only affects Microsoft windows 10/11 windows 7 is not an issue nor is Apple OS.
@PowerUsr1
@PowerUsr1 2 жыл бұрын
Thanks for the education on this. I really don’t get this UniFi product line.
@la009895
@la009895 2 жыл бұрын
So I have a UDM (non pro) and I need a VPN connection now from my work laptops back to my home network so all of my traffic will come from my home network. Do I need to set up pfsense or something else to tunnel from a hotel back home and then forwarding back out again?
@aquahootis9119
@aquahootis9119 Жыл бұрын
Can you do one on troubleshooting ipsec tunnels through the UDM PRO? Connecting to a juniper has been a nightmare. Appreciate all you do
@alexZWL
@alexZWL Жыл бұрын
Not sure if this video is outdated. I have now better options under VPN server. Is saw in this video the option but you were setting it ip under teleport.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
It is dated, they have fixed many of the issues.
@moemanm1202
@moemanm1202 2 жыл бұрын
you should do a comparison between Aruba instant on and unifi aps
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
I just did a test with the AP25rw here at home..
@stijnphilips
@stijnphilips 2 жыл бұрын
@@JasonsLabVideos and?
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
@@stijnphilips It's nice. Video is on my channel.
@danimoosakhan
@danimoosakhan Жыл бұрын
Can you do split tunneling with Wireguard (without UID)? When I import the config in the Wireguard VPN client, it routes everything (including internet traffic) through UDM. Is there a way to enable split tunneling and only route internal LAN traffic through UDM? I know this is possible via the UID VPN client, but I don't want to use UID.
@perovic96
@perovic96 Жыл бұрын
Does openVPN work with DDNS? On normal OpenVPN you’d normally just use domain name instead of IP, does that still work with Unify? Thanks
@online_now6834
@online_now6834 Жыл бұрын
how do you get devices on the wireguard subnet to see local resources? I have my WG devices on subnet 192.168.10.X and home devices on 192.168.1.X and devices on my WG cannot see my home devices at all.....
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Жыл бұрын
Make sure you have the proper routing rules
@markloughtonUK
@markloughtonUK 2 жыл бұрын
Please educate me on your t-shirt. Normally you would have (red, green blue) but the last 2 foxes are switched round. My OCD tells me this is not correct. Please explain :)
@konstantinos4395
@konstantinos4395 Жыл бұрын
Wireguard is a thing now, natively supported
2 жыл бұрын
And this bullshit is why I will never use proprietary (closed source) router if I can choose :D
@rsmakishi
@rsmakishi 2 жыл бұрын
Speaking of simple things Ubiquiti doesn’t care about, there is still no Live View Only accounts for Unifi Protect, maybe because the Ubiquiti solution is to buy the $200 ViewPort.
@nubaus
@nubaus 2 жыл бұрын
Crosstalk did a video years ago using a raspberry pi works awesome to display cameras on TV or monitor.
@michaelwmcdonald
@michaelwmcdonald Жыл бұрын
@@nubaus I run 2 Pi's for this purpose but beware that the code is no longer being updated and only works on Pi3 with older Raspi. It's the support of the video player that changed. I saw on git that he may update it to VLC in the future.
@meteailesi
@meteailesi 2 жыл бұрын
Unifi still cant use openvpn site to site vpn. :@
@waynenocton
@waynenocton 2 жыл бұрын
Could you do a DMZ to a separate router or machine with OpenVPN on it?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 2 жыл бұрын
You could
@waynenocton
@waynenocton 2 жыл бұрын
@@LAWRENCESYSTEMS I am in the middle of replacing a network and I did their VPN with OpenVPN but once I get the UniFi system up, I will have to figure something out, can DMZ to their old router and should work instantly as long as the new firewall rules allow it. Your videos have been very helpful.
@waynenocton
@waynenocton Жыл бұрын
Struck out on this, so strange, if I go into the old UI I can see a network for the VPN that’s not there I’m the new UI. Tried to forward VPN traffic to the old router but it wouldn’t allow me to forward to ports 500 or 4500, due to that hidden network I assume. I read a post saying if you create the radius user from the new UI, it causes a bug that can’t be fixed without a factory restore and total reconfiguring of the network! All at a business that can’t allow much ti be done while they are open, but the minute they get close they want to lock up and go home. Rock and a hard place.
@Sertsch
@Sertsch 2 жыл бұрын
I don't understand why it is so hard to just implement a simple OpenVPN solution into UnifiOS. Something like the VPN Server on Synology DSM would be enough for start -> Simple to configure and just works. It's just pathetic. And then later on with AD / LDAP integration -> perfect. If they had it, Unifi Firewalls would be the perfect solution for many many smbs....
@tjmarx
@tjmarx Жыл бұрын
Why is it so hard to understand why UniFi won't do that?
@tjmarx
@tjmarx Жыл бұрын
Well@@NoName-lq6vw you seem to be under the misunderstanding that UniFi are are charity looking to make your life easy for the sake of good feelings. They're not. They're a for profit enterprise and commercial hardware manufacturer whom set themselves apart by not charging for their dashboard. They're unconcerned about the consumer market because that's not where the money is made. A consumer buys a few thousand dollars worth of equipment, an enthusiast consumer maybe even ten or more thousand worth of equipment. But a health department, hotel chain, sports stadium or enterprise customer is dropping a million, 5 million, 10 million on hardware and Ubiquity need to incentivise those customers to spend as much of that on UniFi hardware as possible. Those kinds of customers aren't trying to block ads on TVs because any TVs those customers have run through closed loop networks where they have end to end control, or direct agreements with a third party whom do. Ubiquity have listened to enterprise customers and their needs. That's what's being built out. If you want open source get an open source gateway solution. Build a pfsense box or buy one off the shelf. Whilst UniFi can be deployed in your home, soho or ultra small business, that isn't it's intended use case. Those aren't the target customers. So you shouldn't be upset when they aren't focusing on the needs of those users. There are plenty of excellent consumer and soho focused appliances on the market that are better suited for those customers and their needs.
@PatrikGillgren
@PatrikGillgren 2 жыл бұрын
Just use pivpn for the time being while Ubiquiti get their shit together and provide a client for linux/osx/windows...
@fo4imtippin
@fo4imtippin 2 жыл бұрын
I run wireguard from the kernel on the udmp. Nice to have an easy option for most though.
@TechySpeaking
@TechySpeaking 2 жыл бұрын
First
@cdoublejj
@cdoublejj 2 жыл бұрын
"is not wrong" you miss pronounced "crock of shit"
@jagdtigger
@jagdtigger 2 жыл бұрын
**puts tinfoil hat on** With all these cloud tie-ins (or should i say lock-in?) i have a sinking feeling that subscriptions arent far off the horizon....
@iankester-haney3315
@iankester-haney3315 2 жыл бұрын
Ubiquiti gear works good for my purposes. A little hacking for vlan routing through wan2 and it's all good. VPN is a nice to have, but not essential.
pfSense vs UniFi Firewall: May 2024 Edition
23:30
Lawrence Systems
Рет қаралды 74 М.
ROLLING DOWN
00:20
Natan por Aí
Рет қаралды 11 МЛН
Gli occhiali da sole non mi hanno coperto! 😎
00:13
Senza Limiti
Рет қаралды 19 МЛН
Which VPN To Use In pfsense?
11:43
Lawrence Systems
Рет қаралды 85 М.
Unifi VPNs 2024: Site Magic, Teleport, Wireguard
17:12
Mactelecom Networks
Рет қаралды 29 М.
UniFi Wireguard VPN (And Firewall Rules)
14:11
Tech Me Out
Рет қаралды 21 М.
Unifi Network Complete Setup 2024
43:19
Mactelecom Networks
Рет қаралды 84 М.
How To Setup VLANs With pfsense & UniFi 2023
21:57
Lawrence Systems
Рет қаралды 193 М.
UniFi Network - Wireguard VPN Access
34:37
MrTimTech
Рет қаралды 10 М.
Tutorial: pfsense Wireguard For Remote Access
27:20
Lawrence Systems
Рет қаралды 157 М.
BEST WiFi Optimization Settings!
20:25
Crosstalk Solutions
Рет қаралды 336 М.
ROLLING DOWN
00:20
Natan por Aí
Рет қаралды 11 МЛН