UniFi lets you administer all of a company’s sites from one dashboard and join their networks with Site Magic, Ubiquiti’s licence-free SD-WAN function. For remote work it offers WireGuard and OpenVPN servers, and to connect with other brands’ equipment, IPsec tunnels. Each site needs its own Cloud Gateway.
Ways to connect sites and users
| Option | What it does | When to use it |
|---|---|---|
| Site Magic | Joins the networks of several UniFi sites automatically | Every site has a UniFi gateway. |
| IPsec or OpenVPN site-to-site VPN | Standard tunnel between two routers | One site has another brand’s router. |
| WireGuard or OpenVPN server | A user’s access to the company network | Remote work and travelling technicians. |
| Remote management | Viewing and configuring the network without a tunnel | Administration and support. |
One dashboard for every site
Each site has its console, and they all appear in the same dashboard with their status, alerts and pending updates. Ubiquiti states that the number of sites is unlimited and that cloud management has no fees.
Different permissions can be given per person: a manager sees every site and a supervisor only their own.
What is shared between sites
Joining sites does not mean opening everything. We define which networks at each site see each other and under what rules, so a problem in a shop does not reach head office.
- File servers, NAS and internal applications.
- IP telephony with internal extensions between offices.
- Cameras from every site in one view.
- Users and access credentials valid at several sites.
Continuity: dual line and standby gateway
- Two internet lines per site, for example fibre and 5G, with automatic failover.
- UniFi 5G modems that connect by PoE and are placed where coverage is best.
- At critical sites, a second standby gateway that takes over if the main one fails.
- A UPS for the comms cabinet.
Planning before you start
- Different address ranges at each site, so they do not overlap when joined.
- The same VLAN names and numbers at every site.
- Internet lines with enough upload speed: it is what limits traffic between sites.
- One admin account per person, with two-factor authentication.
- Documentation for each site and backups of its configuration.
When another solution is better
If the sites already have another brand’s routers that work well, or tunnels with many custom rules are needed, a WireGuard or IPsec VPN with MikroTik may be more suitable. Our guide on site-to-site VPNs compares both options.