Set Up One-Click VPN
  • 03 Apr 2023
  • 2 Minutes to read
  • Dark
    Light

Set Up One-Click VPN

  • Dark
    Light

Article Summary

Requirements

Notes
  • If you have already set up UniFi Identity OpenVPN, it must be deleted before WireGuard VPN can be set up.
VPN TypeDevice RequirementsApplication Requirements
OpenVPN
  • Dream Machine (UDM)
  • Dream Machine Pro (UDM Pro)
  • Dream Machine Special Edition (UDM SE)
N/A
WireGuard VPN
  • Dream Machine (UDM)
  • Dream Machine Pro (UDM Pro)
  • Dream Machine Special Edition (UDM SE)
  • Cloud Key Gen2 Plus (CKP)
  • UniFi Dream Wall (UDW) (EA)
  • UniFi Identity Agent: v1.51.1 or later
  • Identity mobile app for Android: v0.55.2 or later
  • Identity mobile app for iOS: v0.55.4 or later
  • Identity desktop app for macOS: 0.55.1 or later
  • Identity desktop app for Windows: 0.55.1 or later

Set Up One-Click VPN

  1. Sign in to your UniFi Identity Manager (https://[your workspace domain].ui.com/cloud).
  2. Select a site from the drop-down menu in the top left corner.
  3. Go to the dashboard.
  4. Click One-Click VPN.
  5. Click Set Up on the following page.
  6. Configure the VPN settings as needed (see the table below for more information).
SettingAction
NameEnter the network name.
Assign to all users of the current siteEnable to automatically assign this VPN to all users of the selected site.
Deploy onSelect the UniFi Host that will host the VPN.
TypeUniFi Identity currently supports OpenVPN and WireGuard VPN.
VPN ServerSync with the Public IP of UniFi Host: When enabled, the VPN server will auto sync with the public IP address of UniFi OS Host. It's suggested to enable this option if you are using dynamic IPs.
  • Option1: Enable Sync with the Public IP of UniFi Host.
  • Option2: Disable Sync with the Public IP of UniFi Host, and enter the public IP address of UniFi Host.
ProtocolSelect the network's protocol.
Notes:
  • You cannot modify an outer VPN port if your UniFi Host's public IP is the same as the WAN IP.

  • If your public IP and the WAN IP are different, you will need to create a port forwarding rule. For more details, see Network Deployment.



8. Click Show Advanced Settings to configure the following settings (Optional).

SettingAction
Gateway IP/SubnetEnter an IP address.
DNS Server 1Enter an IP address for the primary DNS server.
DNS Server 2Enter an IP address for the secondary DNS server.
Default DNS SuffixEnter the DNS Suffix.
Default DNS Suffix allows administrators to set a DNS suffix that is automatically filled following the hostname element. This means that Windows clients only need to enter the hostname element to access resources through their FQDNs.
Custom RoutingSpecify which IP address or subnet will be routed through the One-Click VPN tunnel when VPN Proxy is set to the Intranet mode.
Custom routing allows the configured IP addresses or subnets to still go through the One-Click VPN tunnel when the client is set to the Intranet mode. Without the need to route all traffic through the One-Click VPN tunnel, employees working remotely can use One-Click VPN to simply access the resources that are accessible only from the company network. The Intranet mode can significantly reduce the bandwidth usage coming from the One-Click VPN-connected clients, and in turn increase the internet speed of One-Click VPN.
Note: This function only applies to clients using the Intranet VPN Proxy mode, the Global mode will still route all traffic through the VPN tunnel.
Maximum Connection TimeSpecify the VPN session duration.
  1. Click Continue. A setup confirmation message will appear.
  2. Click OK.

Was this article helpful?