UniFi Site to Site VPN Setup (And Firewall Rules)

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ม.ค. 2025

ความคิดเห็น • 22

  • @TechMeOut5
    @TechMeOut5  3 ปีที่แล้ว

    *If you liked this video, please give it a like*

  • @alphanetworks7475
    @alphanetworks7475 3 ปีที่แล้ว +1

    I like your "style" of doing things in UniFi security-wise

    • @TechMeOut5
      @TechMeOut5  3 ปีที่แล้ว

      Thank you for watching!

  • @omarvalera5158
    @omarvalera5158 3 หลายเดือนก่อน

    Tech Me Out this video absolutely helped me out. Thanks!

  • @TheHesster
    @TheHesster 2 ปีที่แล้ว +1

    Would you consider making a video going over firewall rules to allow traffic only one direction over the site-to-site vpn? I can't seem to figure it out. I want to be able to reach the remote subnet from local but remote shouldn't be able to reach my local subnet.

  • @WunderTechTutorials
    @WunderTechTutorials 3 ปีที่แล้ว

    Awesome video! Love the explanation on the firewall rules, super helpful - great job!

    • @TechMeOut5
      @TechMeOut5  3 ปีที่แล้ว

      Thank you so much! Much appreciated

  • @AlexH-v4q
    @AlexH-v4q 10 หลายเดือนก่อน

    Hi there, have you managed to connect an AWS VPN to a UDM? I am struggling with this

  • @officefootballpool2088
    @officefootballpool2088 3 หลายเดือนก่อน

    Good video, thanks. When you set up the firewall rules to allow traffic, does that mean that all the traffic from that subnet will always go through the VPN? Or do you need a rule saying everything from subnet x will always go through the VPN (and not through the local gateway)?

  • @srh_btk
    @srh_btk 8 หลายเดือนก่อน

    Why when you are creating firewall rules, the direction for both rules is LAN in? When your Vlans go to the remote side is OK. Its LAN in, but when the remote vlans comes to your LAN it is LAN out, isn't it?

  • @cliffprescott3112
    @cliffprescott3112 3 ปีที่แล้ว

    Exactly what i was looking for. thanks!

    • @TechMeOut5
      @TechMeOut5  3 ปีที่แล้ว

      Glad it was helpful!

  • @liran2611
    @liran2611 3 ปีที่แล้ว +1

    It's a great method you got there but it's funny how much hard work you need to do where in fortigate firewalls no traffic can flow on the tunnel unless you define firewall rules is the default. Ubiquiti are so wierd for not doing it by default

  • @jptrudeauful
    @jptrudeauful 2 ปีที่แล้ว

    Thanks for the Video! Question.. do you know if we could have a Tunnel Between a site that has a static IP and another that got a dynamic one? I wonder if Unifi has a setting for that oneway authentication config.. I asked the support but they seems to not understand my question.. Thanks in advance!

    • @TechMeOut5
      @TechMeOut5  2 ปีที่แล้ว +1

      Thanks for watching. I understand your question but the simple answer is that unlike other vendors, in unifi vpn is being kept very basic and thus there is no one way initiation of the vpn tunnel. Whats more annoying is the fact that ubiquiti has chosen to only allow ip addresses in the host field, if they were to support hostnames or fqdn we would have option at least to use ddns hostnames. Annoying.

    • @iStiflock
      @iStiflock 2 ปีที่แล้ว

      In my experience it will work with dynamic, however, as you know the dynamic ip will change so if it does then your tunnel will stop wrong until you change to the new ip that has been given on the dynamic side.

  • @danimoosakhan
    @danimoosakhan 2 ปีที่แล้ว

    Why can't block all inter-vlan routing by blocking from RFC1918 to RFC1918 on both sides. This will create implicit deny.

  • @PabloTBrave
    @PabloTBrave ปีที่แล้ว

    If you just block all rfc 1918 to all rfc 1918 traffic it would stop intervlan traffic in one rule. You also dont balck access to other gateways or access to controller management console or ssh.

  • @ronan4681
    @ronan4681 ปีที่แล้ว

    Your block all rules don't block access to the gateway itself, so VPN site can access local site gateway and potentially control it

  • @iStiflock
    @iStiflock 2 ปีที่แล้ว

    Does it matter if both devices are on the same console?

    • @TechMeOut5
      @TechMeOut5  2 ปีที่แล้ว

      What do you mean by on the same console?

  • @morap90
    @morap90 4 หลายเดือนก่อน

    Anybody having issues resolving windows DNS service to site2site remote subnets? My config works likely this video, however ( 53 UDP) dns or http (80) service is not getting any response from source server in the origin site. I assume its more related to inter-vlans rules but any of the suggestions rules work for me!!