In this guide, we will walk you through the process of configuring IPSEC Tunnels to interconnect Ubiquiti UniFi device to a Zscaler node for Cloudi-Fi Captive Portal detection.
Prerequisites
Before you begin, ensure you have the following prerequisites in place:
- Access to Cloudi-Fi Admin Console and your Zscaler tenant: You must have access to the Cloudi-Fi admin console, and your Zscaler tenant should be configured.
- Understanding of Your Network, Subnets, and Firewall Configuration: Clearly understand your network topology, subnets, and configuration.
- Access to Ubiquiti Cloud Gateway: Access to your UniFi dashboard.
Before completing the configuration of the IPSEC Tunnel, you need to know on which Zscaler Cloud your tenant has been configured. To find the answer, please connect to your Zscaler tenant and go to Administration > Account Management > Company Profile. Under Organization > General Information, you should find your Company_ID, which is composed of a Zscaler Cloud name associated with numbers. (eg. zscaler.net-123456)
Keep in mind the Zscaler Cloud name, as it will be useful to complete the next actions.
1. Setting up the VPN Tunnel
Add a new VPN Profile named "Zscaler for Cloudi-Fi" : Settings > VPN > Site-to-Site VPN > Create New
Configure the following criteria:
- VPN Type: IPSEC
- Name: eg. Zscaler for Cloudi-Fi
- Pre-Shared Key: Please use the one you have set in your Location Network Parameters within Cloudi-Fi Dashboard
- Local IP: Select the IP used to go to Internet
- Remote IP / Hostname: Please select the proper Zscaler node the closest to your location - Select the Zscaler Cloud on the top of page and then choose the closest node to your location by selecting the VPN Hostname.
-
Network Configuration
- VPN Method: Route Based
- Tunnel IP: Checked
- IP address: Use an IP address which is not overlapping in your current network infrastructure (eg. 10.254.254.1/30)
-
Advanced
- Key Exchange Version: IKEv2
- IKE Encryption: AES-256
- IKE Hash: SHA256
- IKE DH Group: 14
- IKE Lifetime: 86400
- ESP Encryption: AES-256
- ESP Hash: SHA256
- ESP DH Group: 14
- ESP Lifetime: 43200
- PFS: Checked
- Local Authentication ID: Use your FQDN configured in the Location Network Parameters in the Cloudi-Fi Admin Console.
- Remote Authentication ID: Auto
- MTU: 1400
2. Interface Configuration
Before completing the configuration, it is required to set the Guest Vlan in advance.
To rely on Cloudi-Fi DHCP, please follow THIS GUIDE.
To configure a new interface, add a new network for the Guest management: Settings > Networks > Create New
Configure the following criteria:
- Name: eg. <Vlan-ID>-Cloudi-Fi
- Router: Select your device with the role of Router in your infrastructure
- Zone: Internal
- IPv4: Configure the subnet according to your network architecture policy
- Auto-Scale Network: Checked
- Vlan ID: Configure based on your infrastructure
- Select Manual
- Isolate Network: Checked
- Allow Internet Access: Checked
- DHCP Mode: Server
- DHCP Guarding: Checked
- Auto Default Gateway: Checked
- Auto DNS Server: Unchecked - Specifies public DNS servers (eg. 8.8.8.8; 8.8.4.4; 1.1.1.1; ...)
3. Configure the PBR
Add a new PBR rule: Settings > Policy Engine > Policy Table > Filter on Policy-based Routes > Create a new Policy
Configure the following criteria:
- Policy: Route
- Name: eg. Guest-Zscaler
- Type: Policy-Based
- Interface/VPN Tunnel: Select the one you created in 1. Setting up the VPN Tunnel
- Kill switch: Checked
- Source: Check Device/Network + Select the Guest Vlan you have configured
- Destination: Any
Troubleshooting
After completing the above steps, you can verify if the tunnel is UP on the UniFi Dashboard: Settings > VPN > Site-to-Site VPN > Column Uptime
Another way to verify the tunnel establishment is to verify the communication between your router and the Zscaler nodes: Insights > Flows.
From this menu, filter with the source (your router) and the destination which is the Zscaler node.
What’s next?
For more information about our solutions integrated with Zscaler, including a how-to video and a comprehensive solution brief, please visit our partner page.