Skip to content

How to Set Up WireGuard on UniFi and Ubiquiti Gear

Turn on WireGuard VPN in your UniFi gateway and connect remote devices in about 20 minutes. No config files needed, just a few clicks in the Network app.

Remote Access 10 min read
A close-up photograph of a modern home router with blue LED lights glowing softly, positioned on a wooden desk with a laptop blurred in the background showing a network management interface. Warm, neu

Setting up a VPN used to mean wrestling with config files and hoping you'd typed the right key correctly. WireGuard changed that, and UniFi made it even easier by baking it straight into the Network application. If you've got a UDM Pro, Cloud Gateway, or another UniFi console, you can have a working wireguard vpn setup on UniFi in about 20 minutes, no separate software required.

This guide walks through the whole process: turning on the built-in VPN server, adding devices as clients, and getting everything connected from your phone or laptop. We'll also cover the older EdgeRouter line for anyone still running that gear, plus WireGuard setup on TP-Link and Omada routers if you're using those instead. Expect this to take 20 to 40 minutes depending on how many client devices you want to set up, and you don't need any networking certifications to follow along.

What You'll Need

  • A UniFi gateway that supports the built-in VPN server (UDM, UDM Pro, UDM SE, UDM Pro Max, or Cloud Gateway models)
  • The UniFi Network application, either on the console itself or accessed remotely
  • Admin access to your UniFi account
  • A device to connect with (phone, laptop, or tablet) with the WireGuard app installed
  • For EdgeRouter owners: SSH access or the EdgeOS web interface, plus basic comfort with command-line steps
  • A rough idea of which devices or people need remote access

Step 1: Confirm Your Gateway Supports It

Before anything else, check that your hardware can actually run the UniFi VPN server. Most current UDM and Cloud Gateway models support it natively through the Network app's settings.

  1. Log into the UniFi Network application.
  2. Go to Settings and look for VPN in the left-hand menu.
  3. If you see a WireGuard VPN Server option, you're good to go.

Older UniFi Security Gateways and some early UDM firmware versions don't include this feature, so you may need a firmware update first. Head to Settings > System > Updates and install anything pending before you continue.

Step 2: Turn On the WireGuard VPN Server

This is where the actual wireguard vpn setup for UniFi happens, and it's refreshingly simple compared to the old OpenVPN route.

  1. In the UniFi Network app, navigate to Settings > VPN > VPN Server.
  2. Select WireGuard as the VPN type (UniFi may also offer Teleport, which is a simplified wrapper around WireGuard, but we're setting up the standard version here for more control).
  3. Click Create New or Enable depending on your version.
  4. Give the VPN a name you'll recognise later, something like "Home Remote Access".
  5. UniFi will automatically generate a server key pair and choose a default subnet for VPN clients. You can leave these as they are unless you already have a conflicting IP range elsewhere on your network.
  6. Note the port UniFi assigns (often in the 51820 range). You'll need to make sure this is reachable from outside your network.
  7. Save your changes.

At this point the server is running, but nothing can connect to it yet because you haven't added any clients.

Step 3: Check Your Internet Connection and Port Forwarding

WireGuard needs to be reachable from the outside world, which usually means your gateway's WAN IP address needs to accept incoming connections on the chosen port.

  1. If your UniFi gateway sits directly on the internet connection (no modem doing its own routing), UniFi typically handles the forwarding automatically when you enable the VPN server.
  2. If you have a separate modem or ISP-provided router in front of your UniFi gateway, log into that device and forward the WireGuard port (UDP) to your UniFi gateway's IP address.
  3. If your ISP uses CGNAT (common with some mobile and satellite providers), you won't have a public IP to forward to at all. In that case, look at UniFi's Teleport feature instead, since it works around this using Ubiquiti's relay service.

A quick way to check if your public IP is static or changes regularly: visit a site that shows your IP address, note it down, and check again in a day or two. If it changes often, you'll want a dynamic DNS setup so your VPN clients can always find your home network, which is also worth considering if you're planning on anything like the setup described in our guide to hosting a website from home.

Step 4: Add Your First VPN Client

Now for the part that actually lets you connect. UniFi manages WireGuard clients as individual profiles, each with its own key pair.

  1. Still in Settings > VPN > VPN Server, find the section for clients or profiles under your new WireGuard server.
  2. Click Add Client (wording varies slightly between firmware versions, sometimes it's "Create New User").
  3. Name the client something recognisable, like "Dave's Phone" or "Work Laptop". This matters more than it sounds once you have five or six devices connected.
  4. UniFi generates a QR code and a configuration file for this client.

This is the easiest part of setting up wireguard vpn in UniFi, because you don't need to manually copy keys or edit text files at all.

Step 5: Connect Your Device Using the WireGuard App

  1. Install the official WireGuard app on your phone, tablet, or laptop (available for iOS, Android, Windows, macOS, and Linux).
  2. Open the app and choose Add Tunnel or Scan QR Code.
  3. If you're on the same device where the UniFi app is open, scan the QR code UniFi generated in Step 4. If you're setting this up on a different device, download the configuration file from UniFi and import it instead.
  4. Give the tunnel a name in the WireGuard app, then save it.
  5. Toggle the connection on.

Within a few seconds, you should see a handshake confirmation and your device will show as connected inside the UniFi Network app under the VPN section. That confirms your wireguard vpn setup for UniFi is actually working, not just configured.

Step 6: Test Access From Outside Your Network

Don't just trust the green tick in the app. Actually test it properly.

  1. Disconnect your test device from home Wi-Fi and switch it to mobile data or another network entirely.
  2. Turn on the WireGuard tunnel.
  3. Try accessing something on your home network, like a NAS, a smart home dashboard, or a self-hosted service. If you're running anything like the setups described in our beginner's guide to self-hosting at home, this is a good moment to confirm you can reach it remotely.
  4. Check that your public-facing IP address (visible to websites) now shows your home connection, confirming traffic is routing through the VPN correctly.

If it doesn't connect, double check the port forwarding from Step 3 and make sure your firewall rules on the UniFi gateway aren't blocking the WireGuard port.

Step 7: Add More Clients as Needed

Repeat Step 4 and Step 5 for every additional device or person who needs access. Each client gets its own unique key pair, which means you can revoke access for one device without disturbing anyone else. This matters for security reasons covered in our home network security checklist, since shared credentials are one of the easier mistakes to make with remote access tools.

A sensible approach:

  • Create a separate client for each person, not each household.
  • Name clients clearly so you can identify and remove old ones later.
  • Remove or disable clients for devices you no longer use, like an old phone sitting in a drawer.

Step 8: Setting Up WireGuard on Older EdgeRouters

If you're running an EdgeRouter rather than a UniFi console, the process is more manual but still manageable. EdgeOS doesn't have the same point-and-click wizard, so expect to do a bit more work in the command line.

  1. SSH into your EdgeRouter using a terminal application, or use the EdgeOS web UI's CLI tool.
  2. Check your firmware version supports WireGuard. Many EdgeRouter models need a firmware update to EdgeOS 2.0 or later, since WireGuard support was added in more recent releases.
  3. Generate a key pair on the router: `` wg genkey | tee privatekey | wg pubkey > publickey ``
  4. Create a WireGuard interface configuration, typically something like: `` set interfaces wireguard wg0 address 10.10.10.1/24 set interfaces wireguard wg0 listen-port 51820 set interfaces wireguard wg0 private-key /config/auth/privatekey ``
  5. Add a peer (your client device) with its own public key and allowed IPs.
  6. Set up firewall rules to allow traffic on the WireGuard port, and add a static route or NAT rule if you need clients to reach your full LAN rather than just the router itself.
  7. Commit and save your configuration.
  8. On the client side, create a matching WireGuard profile pointing to your EdgeRouter's public IP, port, and public key.

This is noticeably more hands-on than the UniFi Network app experience. If you're not comfortable editing router configs directly, it might be worth checking whether your EdgeRouter can be swapped for a UniFi gateway down the line, especially if you're already relying on remote access regularly. For general router configuration guidance beyond VPNs, our router settings explained guide covers what's safe to change and what to leave alone.

Common Mistakes to Avoid

  • Forgetting port forwarding when there's a separate modem in front of the UniFi gateway. The VPN server can be perfectly configured and still unreachable if the modem isn't passing traffic through.
  • Reusing the same client profile across multiple devices. This makes it harder to revoke access later and muddies your connection logs.
  • Not testing from an actual external network. Testing while still connected to home Wi-Fi can give a false sense that everything works.
  • Ignoring CGNAT on mobile or satellite connections. If you don't have a real public IP, standard port forwarding won't work, and you'll need Teleport or a different approach.
  • Leaving old or unused client profiles active. Every unused VPN profile is a potential access point nobody's watching.
  • Overlapping IP ranges. If your VPN subnet matches your home LAN subnet, devices can get confused about where to send traffic.

Conclusion

Getting a wireguard vpn setup on UniFi running is one of those jobs that sounds intimidating but turns out to be mostly clicking through a few settings screens. The built-in server on UDM and Cloud Gateway devices handles the hard parts, key generation, encryption, and client management, so you're mainly just naming things and scanning QR codes. EdgeRouter owners have a bit more manual work ahead, but the payoff is the same: secure access to your home network from anywhere, without exposing services directly to the internet. Once it's running, it's worth testing every few months, especially after firmware updates, to make sure nothing's quietly broken in the background.

FAQ

Do I need a static IP address for WireGuard to work?

Not necessarily. A static IP makes things simpler, but dynamic DNS services can handle a changing IP address just fine. If you're behind CGNAT with no public IP at all, you'll need UniFi's Teleport feature or a different workaround instead.

Can I use WireGuard and Teleport at the same time?

Yes, they can coexist on the same UniFi gateway. Teleport is really just a simplified, relay-assisted version of WireGuard aimed at easier setup, so running both gives you flexibility depending on the device and network you're connecting from.

Why can't I access devices on my LAN after connecting?

This usually comes down to allowed IP ranges in the client configuration, or a firewall rule blocking VPN traffic from reaching your main network. Double check that the VPN subnet has routes to your LAN and that UniFi's firewall isn't treating VPN clients as untrusted by default.

Is WireGuard actually secure enough for home use?

Yes, WireGuard uses modern, well-regarded cryptography and has had considerable security scrutiny since its release. It's generally considered at least as secure as older VPN protocols like OpenVPN, while being faster and simpler to configure correctly.

Does running a VPN server slow down my home internet?

Not noticeably for typical home use. The encryption overhead is small, and UniFi gateways with hardware acceleration handle WireGuard traffic efficiently. You might notice some impact only if many devices are streaming large amounts of data through the tunnel simultaneously.

What happens if I lose access to the UniFi app and need to reconfigure things?

As long as you can still reach your UniFi gateway on the local network or through the cloud console, you can log back in and adjust VPN settings as needed. It's a good idea to keep a backup admin account and, if you're troubleshooting wider connectivity issues, our guide to diagnosing home network problems can help rule out other causes before assuming the VPN itself is broken.

A person's hands operating a laptop keyboard in a home office, with a desktop monitor visible on the desk showing a different screen, suggesting remote control between devices. Warm, neutral lighting
Remote Access October 7, 2026 • 7 min

How to Set Up Remote Desktop on Your Home Network

Learn how to set up remote desktop on your home network in 15 to 30 minutes. Control one PC from another using Windows built-in tools or free alternatives…

A person using a laptop at a home desk with a second monitor displaying a different desktop environment, shown in soft natural daylight from a nearby window, conveying ease of access and control with
Remote Access October 7, 2026 • 7 min

Best Remote Desktop Software for Home Use

Compare the best remote desktop software for home use, from free options like Chrome Remote Desktop and RustDesk to paid tools like AnyDesk and TeamViewer.