UniFi Identity VPN setup

Hey all, I’ve been trying to use UniFi Identity One-Click VPN to reach back home.

My issue is that my Android phone can only use 1 VPN, and when using the One-Click VPN all my traffic goes through the WAN1 interface.

When connected to the One-Click VPN I want all traffic destined for the internet to go through my 3rd-party privacy VPN that is configured as a VPN client on the UniFi console instead of WAN1.

But for the life of me I cannot figure out how to do the policy routes. I can’t select the VPN network at all during creation or manually give it a IP address or scope.

Do I need the UID enterprise for this or is it just straight up not possible?

Appreciate any help or guidance.

Best regards

I don’t think there is a way to come in via the VPN and then redirect the traffic out a privacy VPN. Even if there was I would not recommend doing it that way as I would instead have the phone use the privacy VPN directly.

I’m running PfSense and do exactly what you are asking, I would guess it ought to be possible on your Unifi setup.

I’ve setup a vlan which exits via VPN gateway, I’ve then setup an OpenVPN server which exits via the VPN gateway, hence I only need to connect my OpenVPN server. I would guess that you can do the same thing but you probably need to configure this step by step on your system.

This article might be what you are looking for. UniFi Gateway - Policy-Based Routing. As Tom has said I would instead just have the phone use the privacy VPN directly.

Offering a slightly different solution…

Unifi has an application called “WiFiman” and it’s a one click VPN solution to get you back to your home network. I was surprised how easy it was and it works dang well.

Thank you all for your inputs, very much appreciated.

I should probably have explained my goal better.
I’m currently using the privacy VPN directly on my phone, but I want to be able to use some services I have at home whenever I’m out and about roaming the world.

So I might have gone in the wrong direction with trying to solve my problem?
I want my laptop and phone to be able to use services at my home network, but I also want my exit point for WAN traffic to be the privacy VPN.

Laptop I can easily figure out since it allows more interfaces to be configured, but I was stuck at my Android phone can only use 1 VPN service at a time, so split tunneling wasn’t really working out there for me.

But I also liked to keep it simple, so my thoughts were use UniFi Identity VPN, route WAN traffic through the privacy VPN configured on UniFi Console. But it seems I can only select networks created on the console itself or devices on those networks. I can’t select the VPN servers configured on console or a specific IP- or ranges.
Any other solutions to my issues is greatly appreciated.

Best regards

Do you have a computer of any kind that’s always on at home?