> For the complete documentation index, see [llms.txt](https://docs.monogoto.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monogoto.io/advanced-console/platform/vpn-setup-examples/vpn-setup-with-ubiquiti.md).

# VPN Setup with Ubiquiti

The following guide describes how to setup a secure VPN tunnel between Monogoto account and Ubiquiti.

1\.      Login to the Monogoto portal and go to ***Network.***

2\.      Edit your **“vpneu.mono”** network (EU zone) or **"vpnus.mono"** network (US zone).

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2F7bFo6O07wfIT3aKaX3eM%2F1.png?alt=media\&token=1d18d347-5bfd-421a-b1e7-c00f4be050e6)

3\.      Go to the **VPN** section and select ***Add New.***

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FLF4OrVNpSkJsyMLH3HgH%2F2.PNG?alt=media\&token=86401bd2-8cbd-4c6c-9399-b972e3416d42)

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2Fp6T5cq1hlqGMHEeaO0bK%2F3.PNG?alt=media\&token=6a228c0d-77d0-46ba-84ae-d59903e12905)

* Enter a **VPN Name** of your choice.
* For **Destination IP Address**, enter the **external IP address** of your Ubiquiti gateway.
* For **Destination Network**, enter your LAN’s IPv4 CIDR block.
* For **Pool Name**, select your **Monogoto IP address pool**.

When you are done, click **Save & Close**, and **Apply Settings**.

4\.      Now we need to add a **route** to the VPN in the Monogoto portal.\
Go to the **Routes** select ***Add New***.

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FkuOukEhx7E0Haup61yCu%2F4.PNG?alt=media\&token=db11c0c9-534c-49f7-8040-1d3f80385fca)

* For **Destination**, enter you **LAN CIDR block**.
* For **Gateway**, select the default Monogoto gateway.

Click **Save & Close**, and **Apply Settings.**

5\.      Go back to **Routes** and copy Gateway IP.

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FaWR4bW300Zl2QngaSyjw%2FVpn_Routes.png?alt=media\&token=1eb125fc-72df-496d-9900-1a48fabc753b)

6\.      Go back to the **VPN** section and press the **Download VPN Config** button. Copy the **“Pre-Shared Key”** from the downloaded config file.

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2F5uimgUhQGpP7GPubmxgQ%2F6.PNG?alt=media\&token=d3a20446-4ddf-41b5-82fe-281b48fe63a7)

7\.      On the Ubiquiti web UI, click **“settings” -> “Networks” -> “Add new network”.**

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FdfMIRaG91ITM7Wn4FIms%2Fimage.png?alt=media\&token=6ce76a7f-c256-432a-aacd-37b9ef7d10f1)

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FGRST1jtZmVeiNA3zDjAu%2Fimage.png?alt=media\&token=85a89273-da3c-45e0-b737-ad2a1e64b023)

8\.      Name your new network, expand the **Virtual Private Network** dropdown, select **“Advanced”** and make sure **“Site-to-Site”** and **“Manual IPsec”** are selected.

9\.      Paste the **Pre-Shared Key** we copied from the **VPN Config** into the **Pre-shared Secret Key** field.

* For **Public IP Address**, select the gateway’s external IP address you used when creating the Monogoto VPN.
* For **Remote Gateway/Subnets**, enter the **Monogoto IP Address Pool** **CIDR block** and click “create”. For **Remote IP Address**, enter the **Monogoto Gateway IP** we copied earlier.

![](https://3922449203-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M0mPxGpottOEfcucXOR%2Fuploads%2FTh32b4zC3GvZoRGt0zIn%2Fimage.png?alt=media\&token=ad4074a7-b8a8-4549-87ca-6b1c9aa64371)

10\.      Under **Advanced**, leave everything as-is, but make sure **both DH groups** are set to **2.**

11\.       Click **Add Network**.

12\.      Make sure no firewall rules are blocking VPN traffic.

That’s all – the VPN tunnel should now be connected.
