<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
        <title><![CDATA[Routing & Switching | Topics | Ubiquiti Community]]></title>
        <description><![CDATA[Routing & Switching | Topics | Ubiquiti Community]]></description>
        <link>https://community.ui.com</link>
        <image>
            <url>https://community.ui.com/images/og-image.jpg</url>
            <title>Routing &amp; Switching | Topics | Ubiquiti Community</title>
            <link>https://community.ui.com</link>
        </image>
        <generator>Ubiquiti Community</generator>
        <lastBuildDate>Wed, 30 Sep 2026 21:47:23 GMT</lastBuildDate>
        <atom:link href="https://community.ui.com/rss/topics/unifi-routing-switching" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 30 Sep 2026 21:47:23 GMT</pubDate>
        <copyright><![CDATA[© 2026 Ubiquiti Inc. All rights reserved.]]></copyright>
        <item>
            <title><![CDATA[DNS and other domain services over IPsec site-to-site VPN]]></title>
            <description><![CDATA[<p>I have a very similar issue as in the link below. I have a tunnel between the main site firewall and the remote site Unifi UDW. I have a domain controller at our main site. At the remote site, I can't log in to a domain computer with a domain account. If I have cached credential, I can ping the domain controllers and other resources and navigate to the resources by IP at the main site, but not by name. I have everything disabled as far as ad blocking and content filtering. I have each remote network DHCP services on the UDW pointed to the main site DCs. I did get somethings to work by name by putting in A records in DNS on the UDW at the remote site, and I get asked for credentials when I navigate to resources by name, but it doesn't take it. It says the domain is unavailable. If I missed a post with a fix for this, please, let me know. I haven't found it yet. I have firewall rules that work because it is allowing other types of traffic through.  It seems like it should just forward the DNS traffic through the tunnel, but it never reaches the other side.</p><p><a href="https://community.ui.com/questions/DNS-over-IPSec-site-to-site-vpn/99ee6930-804e-4e6f-84b2-15e8d38a89e1#answer/f047ea34-b553-4868-8e88-bbb00055522f" rel="noopener noreferrer" target="_blank">https://community.ui.com/questions/DNS-over-IPSec-site-to-site-vpn/99ee6930-804e-4e6f-84b2-15e8d38a89e1#answer/f047ea34-b553-4868-8e88-bbb00055522f</a></p>]]></description>
            <link>https://community.ui.com/questions/DNS-and-other-domain-services-over-IPsec-site-to-site-VPN/ea81c033-d754-48f4-b0c6-878dc33756e1</link>
            <guid isPermaLink="false">ea81c033-d754-48f4-b0c6-878dc33756e1</guid>
            <category><![CDATA[wifiman]]></category>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[unifi-routing-switching]]></category>
            <dc:creator><![CDATA[tgardner.ac]]></dc:creator>
            <pubDate>Thu, 01 May 2025 22:52:43 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Site-to-site (Site-magic) stuck on connecting - Wireguard port blocked?]]></title>
            <description><![CDATA[<p>I have 2 sites (UCG - Ultra and UCG-Max) both on the latest official releases where attempting to create a site magic site-to-site VPN results in a 'Connecting' state and never comes up.</p><p>I did some troubleshooting and did notice something peculiar - when I manually create a Wireguard VPN server on my UCG-Max the assigned port is not open. The connectivity is allowed through the firewall and I can create an OpenVPN server on the same site which works fine.</p><p>It looks like the wireguard server is not listening to connections on the UCG-Max and I believe site magic uses Wireguard, hence I suspect that is the cause site magic is unsuccessful.</p><p>Any suggestions on a remedy? I have previously attempted the below:</p><ul><li>Removed any custom firewall rules, NAT, static routes, port forwarding etc. and attempted to delete and create</li><li>Rebooted the UCG-Max and UCG-Ultra</li><li>Tried different port numbers for wireguard</li></ul>]]></description>
            <link>https://community.ui.com/questions/Site-to-site-Site-magic-stuck-on-connecting-Wireguard-port-blocked/308f78fd-9eea-4b72-9d79-42d8186ede5b</link>
            <guid isPermaLink="false">308f78fd-9eea-4b72-9d79-42d8186ede5b</guid>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi]]></category>
            <category><![CDATA[site-manager]]></category>
            <category><![CDATA[unifi-cloud-gateway]]></category>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[unifi-routing-switching]]></category>
            <dc:creator><![CDATA[kashefcom]]></dc:creator>
            <pubDate>Mon, 14 Apr 2025 07:50:56 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[2 Weird UDMP Issues (Multiple Unifi OS Versions)]]></title>
            <description><![CDATA[<p>Hoping to find out if anyone else is experiencing something similar; I've been in the process of moving my lab back to Unifi now that they have so much better feature parity with higher end firewalls, but a few things are limiting me. </p><p><br></p><p>First issue, for some reason, download speeds on my UDMP are incredibly slow, this has been on the last few stable and EA Unifi OS versions, as well as the last few Unifi Controller versions. I've used my UDMP as my main firewall before, and I have an 8 gigabit symmetrical WAN, and have been able to get around 7.5Gbps in both directions with it. But for some reason, now, I can't get more than about 500Mbps download, upload is still in the 7 gigabit range though. Other firewalls I have don't have this issue, for example my Netgate 6100 can hit around 3.5 gigabit in both directions right now (that's the fastest it can route real world). I've tried everything I can think of other than fully factory resetting, might do that though if I can't find another solution.</p><p><br></p><p>Second, and this is in some ways the bigger issue because I do believe the above will be fixed by factory resetting, packet captures just flat out don't work on my UDMP anymore. They did when they were first introduced, but now whenever I try to run a pcap on any interface, it just times out. I get a little notification in the top right that says "packet capture timed out" with no additional info. I use pcaps for troubleshooting and other stuff all the time, so this has to work. </p>]]></description>
            <link>https://community.ui.com/questions/2-Weird-UDMP-Issues-Multiple-Unifi-OS-Versions/f149d019-5995-4282-b417-2a19232ddb41</link>
            <guid isPermaLink="false">f149d019-5995-4282-b417-2a19232ddb41</guid>
            <category><![CDATA[unifi-network]]></category>
            <category><![CDATA[unifi-gateway-cloudkey]]></category>
            <category><![CDATA[unifi-routing-switching]]></category>
            <category><![CDATA[unifi]]></category>
            <dc:creator><![CDATA[planedrop]]></dc:creator>
            <pubDate>Sat, 12 Apr 2025 18:11:28 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[What am I missing: Moving pfSense into Aggregation Switch]]></title>
            <description><![CDATA[<p>I've built out my home network over time and only recently started replacing old TPLink gear with Ubiquiti. I ran into a snag when trying to move my pfSense Protecli router and was hoping for some feedback on what I did wrong or don't understand.</p><p><br></p><p>I have comcast internet coming into the pfSense and the LAN from that going into an RJ45 port of a USW-Pro-24 switch. For numerous home lab reasons I have DHCP handled by the pfSense router, but DNS handled by pihole and Windows Server forwarding for the domain.&nbsp;</p><p><br></p><p>Once I moved to Ubiquiti access points I added a USW-Pro-24-POE to the mix.&nbsp;</p><p><br></p><p>In an effort to add 10Gb connectivity to my network for a VMware vSAN cluster among other things I added the USW-Aggregation which I then connected the PoE and Pro-24 up to via SFP+ DAC.&nbsp;No issues. Works great. </p><p><br></p><p>A small TPLink switch was also connected to the aggregation switch via 10Gtek 1.25/2.5/5/10G-T SFP+ to RJ45 CAT.6a Copper Transceiver set to 1Gb and worked without issue.&nbsp;</p><p><br></p><p>My understanding was that my router should also be going through the aggregation switch rather than hanging off the side of one of the switches so I got another SFP+ to RJ45 transceiver to go about making this change.&nbsp;</p><p><br></p><p>I shut down the pfSense and connected it to the aggregation switch via transceiver setting the port to switching and 1Gbps FDX. I powered it on and switches in unifi just started disconnecting. The switches were dropping to their default IP of 192.168.1.20 because they couldn’t see the DHCP server which is coming from pfSense.&nbsp;</p><p>I tried restarting the aggregation and PoE switches but still didn’t get a correct IP.&nbsp;</p><p>I tried disconnecting DAC connections between aggregation and other switches and re-connecting but that did nothing.</p><p>The second I unplugged the transceiver in port 1 on the aggregation switch it showed the right IP on the front screen and everything popped up in the UI. That transceiver goes to one of the vSAN nodes which has never had an issue with connectivity and after putting everything back the way it was before has been fine since.&nbsp;</p><p><br></p><p>My question is, should the pfSense router be going into the aggregation switch and if so how do I go about getting it moved over without everything failing as it did?&nbsp;</p><p>Thanks</p><p><br></p>]]></description>
            <link>https://community.ui.com/questions/What-am-I-missing-Moving-pfSense-into-Aggregation-Switch/dc77c898-6217-49a6-92db-73ecac815600</link>
            <guid isPermaLink="false">dc77c898-6217-49a6-92db-73ecac815600</guid>
            <category><![CDATA[unifi]]></category>
            <category><![CDATA[unifi-routing-switching]]></category>
            <category><![CDATA[unifi-wireless]]></category>
            <category><![CDATA[unifi-cloud-gateway]]></category>
            <category><![CDATA[unifi-switching]]></category>
            <category><![CDATA[wifiman]]></category>
            <category><![CDATA[unifi-design-center]]></category>
            <dc:creator><![CDATA[minimoose]]></dc:creator>
            <pubDate>Sat, 08 Mar 2025 14:38:25 GMT</pubDate>
        </item>
        <item>
            <title><![CDATA[Current setup and a wish to expand with a wireless AP]]></title>
            <description><![CDATA[<p>My current setup is a UCG Ultra and two UXs as access points, which are wired to the UCG. I want to bring in another access point and for that I need a wireless option - what do you guys suggest me? </p><p>remark: I turned off the wireless meshing feature, because the UXs were not using the wired backbone to the UCG with that turned on. So I am asking for a solution to bring in a wireless access point, which is able to connect to the available wifi that already exists. </p>]]></description>
            <link>https://community.ui.com/questions/Current-setup-and-a-wish-to-expand-with-a-wireless-AP/f7164a99-745f-4823-a116-f706e09112a9</link>
            <guid isPermaLink="false">f7164a99-745f-4823-a116-f706e09112a9</guid>
            <category><![CDATA[unifi]]></category>
            <category><![CDATA[unifi-routing-switching]]></category>
            <category><![CDATA[unifi-wireless]]></category>
            <category><![CDATA[unifi-switching]]></category>
            <dc:creator><![CDATA[punkenciel]]></dc:creator>
            <pubDate>Wed, 05 Mar 2025 11:57:46 GMT</pubDate>
        </item>
    </channel>
</rss>