UniFi USG Firewall
To configure the tunnel in the UniFi USG Management Portal:
-
Log in to the UniFi USG Management Portal with the Administrator account.
-
Click Networks and then click Create New Network.
-
Click Site to Site VPN > Manual IPSec.
-
Enter these:
Field
Enter
Name Name for the network. Purpose Site-to-Site VPN VPN Type Manual IPSec Enabled Select the Enable this Site-toSite VPN checkbox. Remote Subnets
Harmony SASE subnet. The default is 10.255.0.0/16.
Peer IP
Public IP address of the location server.
Local WAN IP
Public IP address of the UniFi USG firewall.
Pre-shared key
Secret key specified in Configuring the Tunnel in the Harmony SASE Administrator Portal.
-
In the Advanced Options section:
Field
Enter
IPsec Profile
Customized
Route Distance
30
Key Exchange version IKEv2 Encryption AES-256 Hash SHA1 IKE DH Group 21 PFS
Enable
Dynamic Routing
Disable1
1 To create a Route-Based IPSEC Site-to-Site connection between Harmony SASE and your Ubiquiti network:
-
Set Dynamic Routing to Enable .
-
Add any other subnet specified in Remote Subnets and make sure that a reverse traffic route is created under Static Routes in the UniFi USG firewall for each connected subnet to route through the Harmony SASE Interface.
-
In the Harmony SASE Administrator Portal, change Harmony SASE Gateway Proposal Subnets and Remote Gateway Proposal Subnets to Any (0.0.0.0/0).
-
Create separate static routing in Harmony SASE. For more information, see <TBD_Cross-ref to site-connection overview>.
-
-
Add static routes from Harmony SASE subnet (10.255.0.0/16) to the local network and vice versa through the VPN gateway:
-
Go to Routing & Firewall > Static Routes > Create New Route.
-
Enter these:
Field
Enter
Name
Name for the static route.
Enabled
Select the Enable this route checkbox.
Type Static Destination Network Harmony SASE subnet. The default is 10.255.0.0/16. Static Route Type Interface Interface Select the interface created in the previous procedure. -
Click Save.
-
-
Create a firewall rule to allow traffic from Harmony SASE subnet to the LAN network.
-
If you have enabled IPS/IDS on the UniFi USG firewall, then to establish a tunnel between the Harmony SASE network and UniFi USG firewall version 7 and later, create an exception in your Threat detection system:
-
Click the Firewall & Security tab.
-
Click Create New Allow List.
-
Select the site-to-site network that you created for this setup.
-
Save your changes.
-