Ubiquiti UniFi Site-to-Site VPN Down Error: How to Fix It
Medium 30-60 minutes High Severity
Verified June 2026
- Error Code
- Site-to-Site VPN down
- Brand
- Ubiquiti UniFi
- Product Type
- networking
- Severity
- High
- DIY Difficulty
- Medium
- Estimated Fix Time
- 30-60 minutes
Ad
Tools You'll Need
- Computer with web browser
- UniFi Network Controller access
- Administrative credentials
- SSH access (if needed)
How to Fix Error Code Site-to-Site VPN down
-
Check VPN tunnel status in UniFi Network Controller
-
Verify preshared key configuration
Changing the preshared key will temporarily disconnect the VPN tunnel until both sites are updated -
Check for subnet conflicts
-
Verify firewall rules and port forwarding
-
Restart the VPN tunnel
-
Check internet connectivity and DNS
-
Update firmware if necessary
Always backup your configuration before firmware updates and schedule updates during maintenance windows -
Review system logs for detailed errors
Parts You May Need
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
UniFi Security Gateway or Dream Machine
Check Price on Amazon
Ethernet cable
Check Price on Amazon
Ad
When to Call a Professional
Contact a network administrator or Ubiquiti support if the VPN remains down after trying these steps, if you're experiencing frequent disconnections, or if you need to redesign your network topology to resolve subnet conflicts. Professional help is also recommended if you're uncomfortable modifying firewall rules or if the issue affects critical business operations.Frequently Asked Questions
Why does my UniFi site-to-site VPN keep disconnecting?
Frequent VPN disconnections are usually caused by unstable internet connections, NAT traversal issues, or aggressive timeout settings. Check your internet stability, ensure proper port forwarding for UDP 500/4500, and consider adjusting DPD (Dead Peer Detection) timeout values in advanced settings.
How do I find the correct remote subnet for my UniFi VPN?
Log into the UniFi Controller at the remote site and check Settings > Networks to see the configured LAN subnets. The remote subnet in your VPN configuration should match the actual network range used at the distant location, typically something like 192.168.1.0/24 or 10.0.0.0/8.
Can I use the same preshared key for multiple UniFi VPN tunnels?
While technically possible, it's not recommended for security reasons. Each site-to-site VPN tunnel should have a unique, strong preshared key. Use a password generator to create complex keys with at least 20 characters including letters, numbers, and symbols.
What UniFi devices support site-to-site VPN?
Site-to-site VPN is supported on UniFi Security Gateway (USG), USG Pro 4, Dream Machine (UDM), Dream Machine Pro (UDM-Pro), and Dream Machine SE (UDM-SE). Basic UniFi access points and switches do not support VPN functionality.
How do I test if my UniFi VPN tunnel is working properly?
Test the VPN by pinging devices across the tunnel from each site. You can also check the VPN status in the UniFi Controller dashboard, review connection logs, and verify that devices on one network can access resources on the remote network through the encrypted tunnel.