timeshifter
Well-Known Member
- Reaction score
- 2,407
- Location
- USA
Trying to establish a site to site VPN with a UniFi Security Gateway Pro 4. We got stuck. Not clear on Phase 1 / Phase 2 settings as UniFi doesn't identify what they're settings refer to. Also, the remote subnet is unclear.
The remote IPs we need to tunnel to is a list of 9 IPs. They look like public IPs, which the vendor confirmed as the application vendor set it up that way, I guess for client VPN connections. Anyway, I need to put those 9 IPs in. But the UniFi fields only allow for a subnet.
Tried putting in 74.156.22.33/32 so the subnet would be a single IP, but it would not save that. I could save it as 74.156.22.33/24 as a test, but of course that won't be a real fix. (Note the IP I put in here is just made up)
Here's a copy paste from the ticket with the vendor, who summarized it well:
"While on the phone you discovered that you were only able to put the entire /24 subnet in the Ubiquity for the remote subnet field and could not put a single host IP. Your plan is to get clarity from Ubiquity support on how to accomplish this. You also will look into the phase 2 settings as we could not tell if the encryption and hash were for the phase 1 or phase 2 part of the tunnel based on the screen shot. Let us know when you are ready to test the tunnel again."
The remote IPs we need to tunnel to is a list of 9 IPs. They look like public IPs, which the vendor confirmed as the application vendor set it up that way, I guess for client VPN connections. Anyway, I need to put those 9 IPs in. But the UniFi fields only allow for a subnet.
Tried putting in 74.156.22.33/32 so the subnet would be a single IP, but it would not save that. I could save it as 74.156.22.33/24 as a test, but of course that won't be a real fix. (Note the IP I put in here is just made up)
Here's a copy paste from the ticket with the vendor, who summarized it well:
"While on the phone you discovered that you were only able to put the entire /24 subnet in the Ubiquity for the remote subnet field and could not put a single host IP. Your plan is to get clarity from Ubiquity support on how to accomplish this. You also will look into the phase 2 settings as we could not tell if the encryption and hash were for the phase 1 or phase 2 part of the tunnel based on the screen shot. Let us know when you are ready to test the tunnel again."
Last edited: