UniFi Access

Connect the VPN

Let your UniFi console open a WireGuard tunnel to SportyPlus, and allow SportyPlus through to UniFi Access

Your console connects out to SportyPlus over WireGuard. You don't forward any ports or change your internet router. This works even when the console sits behind another router, as it often does when the internet provider supplies the main router.

This page has three steps: downloading your club's file from Club Admin, importing it on the console, and one firewall rule. Your club's own network stays as it is: we never route to it, so it doesn't matter what address range it uses, or whether another club uses the same one.

1. Download your club's WireGuard file

In Club Admin → Business → Integrations → UniFi Access, press Create VPN connection under VPN connection. Your browser downloads a WireGuard configuration file (.conf) made for your club, and the card shows your console's tunnel address, for example 10.200.0.3. The console address further down the page is filled in with it for you.

The file holds your club's private key, so treat it like a password: don't forward it or post it anywhere. SportyPlus doesn't keep a copy, so you can download it only this once. If you lose it, press Download a new file. That issues new keys, and the old file stops working within a minute.

The file only sends traffic for SportyPlus's own tunnel address through the tunnel. The rest of your club's internet traffic keeps going out as it does today.

2. Import it on the console

In UniFi Network on your console:

  1. Open Settings → VPN → VPN Client, and choose Create New.
  2. Pick WireGuard as the type and give it a name, for example SportyPlus.
  3. Upload the .conf file we sent you, or paste its contents.
  4. Save, and make sure the client is turned on.

Don't create a traffic route or a policy route for this client. SportyPlus doesn't need any of your traffic sent through it.

"Invalid DNS in Interface. Use: DNS = IP Address" — UniFi won't import a WireGuard file without a DNS line, even though this tunnel doesn't use one. The files we send already contain DNS = 1.1.1.1. If you see this message, the file was edited or is an old one. Add the line DNS = 1.1.1.1 under [Interface] and upload it again, or ask us for a fresh file. A hostname or an empty value is rejected the same way.

Once it's saved, the console connects within a minute or two. The VPN connection card in Club Admin then shows Connected and when the console last made contact. Press Check again to refresh it.

3. Allow SportyPlus through to UniFi Access

By default the console blocks traffic arriving through a VPN client, so this rule is required. Without it SportyPlus reports that it could not reach the console.

In UniFi Network → Settings → Security → Firewall, add a rule:

SettingValue
ActionAllow
Sourcethe SportyPlus WireGuard VPN client, address 10.200.0.1
Destinationthe console itself (Gateway)
Protocol / portTCP 12445 only

Port 12445 is UniFi Access's API. Don't allow more than that: SportyPlus needs nothing else on your network.

The firewall screens differ between UniFi Network versions. On newer versions, rules are set between zones: allow from the VPN zone to the Gateway zone. Whatever the screen looks like, the rule is the same: from 10.200.0.1, to the console itself, TCP 12445, allow.

When it's done

Once the card shows Connected and the rule is in place, create the API token.