UniFi Lab 06
Door Hub LOCK NO/NC wiring
Hub is online. Unlock permission is fine. The lock still will not behave. Check LOCK, not AUX.
Your job: land the primary lock on LOCK, match NC/COM or NO/COM to the lock type, and hear the relay click on unlock.
This run: Break A. Lock on AUX. Unlock permission is already correct.
Lab complete. The primary lock is on LOCK and the relay clicks on unlock.
lock_wired_unlock_clicksLock wired, unlock clicksDoor Hub terminals
Front DoorLOCK
POWERED12V DC up to 1 A
DRYNO POWER · external transformer
Relay LED
AUX
Door operatorDRY
Siren / chimePOWERED 12V
Relay LED
Lock lead: AUX
POWERED: hub 12V DC, up to 1 A.
Lock readout
Sim| Lock type | Fail-safe maglock |
|---|---|
| Terminal | AUX |
| Polarity | NO/COM |
| Power mode | POWERED |
| External 12V | Not applied |
| Relay | Idle |
| Lock | Maglock stays locked. AUX may click. |
Legend
- Lock lead
- AUX (not the lock)
- Relay LED white = unlock
- Up or correct
- Failing symptom
- Teaching contrast
Controls
LOCK vs AUX, NC/COM vs NO/COM, and POWERED vs DRY. Unlock permission is already correct.
Door Hub, Front Door
- Door
- Front Door
- Hub
- UA-Hub class
- Unlock permission
- Already correct (Lab 03)
LOCK power
Test
Listen for the relay click. On a good wire, the LOCK relay LED blinks white.
Illegal move
Blocked. Do not parallel 12V on POWERED. The hub already supplies 12V.
Out of scope for this lab
Why this fails
copy key: lock_on_auxLock wired to AUX
Lock on AUX
Field note: AUX drives door operator or siren/chime. The primary lock belongs on LOCK. Move the lock leads to LOCK, then retest unlock and watch the LOCK LED.
Fix: Move the lock leads from AUX to LOCK, then test unlock.
Why Broken and Fixed
Console words
- Lock on AUXShowing
- AUX is for a door operator or siren/chime. The primary lock belongs on LOCK.Showing
- Fail-safe needs NC/COMClear
- A maglock stays locked only while power is held. LOCK NC/COM drops power on unlock.Clear
- Fail-secure needs NO/COMClear
- A strike needs power to unlock. LOCK NO/COM closes on unlock.Clear
- Do not parallel 12V on POWEREDClear
- Hub onlineShowing
- Front DoorShowing
- Unlock permission already correctShowing
- Lock wired, unlock clicksClear
Fail-safe stays locked on power. Wire LOCK NC/COM. Fail-secure unlocks on power. Wire LOCK NO/COM. AUX is not the lock.
Door Hub terms
This lab- NC/COM
- Fail-safe pair. Unlock opens the relay and drops power so a maglock releases.
- NO/COM
- Fail-secure pair. Unlock closes the relay and applies power so a strike unlocks.
- COM
- Common side of the LOCK relay pair. It lands with NC or with NO, not both.
- POWERED
- LOCK power from the hub: 12V DC, up to 1 A. Do not add a second 12V supply.
- DRY
- NO POWER on LOCK. An external transformer may feed a non-12V load, up to 30V DC / 1 A.
- AUX
- Door operator (dry) and siren/chime (powered 12V). Not the primary lock.
- Fail-safe
- Maglock. It stays locked only while power is held. Wire it to LOCK NC/COM.
- Fail-secure
- Strike. It needs power to unlock. Wire it to LOCK NO/COM.
Glossary
Core, Labs 01 to 03- Native
- Untagged VLAN on a switch port (PVID). Management traffic usually rides here on UniFi device uplinks.
- Tagged
- VLAN IDs carried with an 802.1Q tag on a trunk. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
- Access port
- One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
- Trunk
- Native + tagged VLANs. Correct pattern for UniFi switch to AP / switch to gateway when multiple networks exist.
- ZBF
- Zone-Based Firewall. Policies between zones (Gateway, External, Internal, Guest, etc.), not just classic LAN IN rules.
- Gateway zone
- Where the router answers DHCP and DNS for a network. Block Guest to Gateway and clients get No IP or DNS unreachable.
- Client isolation
- WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
- PoE class
- AF (~15 W), AT (~30 W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
- PoE budget
- Sum of max PD draws vs what the switch or injector can supply. Exceed it and devices disconnect.
- Injector
- Power source for a Flex or similar. Wrong class (AF on a loaded Flex) is a classic field fail.
- Max draw
- Datasheet maximum watts for a PD (IR on, boot). UniFi PoE budget math uses this, not the quiet live reading.
- Flex budget
- USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
- Remote Unlock via Endpoint
- Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
- Door Attendant / receiver
- User assigned to get the door call. Not on the list means no Unlock for that door.
- Inform
- Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
- STUN
- UDP 3478 helper for L3 / remote adoption. GUI on 443 is not the same path.
Fiber terms, glossary ready for later
MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.
Symptom words (overlay language)
Before and after
Diff rows marked| Setting or symptom | Broken start | Now |
|---|
Gear in this lab
- 1 Console
- 1 Door Hub
- 1 Fail-safe maglock
- 1 Fail-secure strike
Config and wiring only. The fix needs no new hub. Counts only, no prices.
Takeaway
Fail-safe on NC/COM. Fail-secure on NO/COM. LOCK, not AUX.
A maglock that stays open, or a strike that never unlocks, is often the relay pair. POWERED means the hub supplies 12V. DRY means an external transformer. Never parallel a second 12V supply onto POWERED.
- Land the primary lock on LOCK.
- Fail-safe maglock: LOCK NC/COM.
- Fail-secure strike: LOCK NO/COM.
- Test unlock. The relay LED blinks white.
BOM delta on win: none. Config and wiring only.
Want Access and a Door Hub set up like this at your place? We design UniFi Access and door entry as part of a UniFi install.
Related labs
All labs /labs
A teaching lab, not a quote and not a design for your site. Terminals are simplified from the UniFi Access Door Hub. No account, and nothing from this lab is saved.