UniFi Lab 09 Site Magic overlapping spokes
Offices: can't reach each other
Fabric up, overlap NATedOur two offices can't reach each other
Connect both offices, even though they use the same addresses.
Not sure where to start? Check Auto-Scale and NAT Spoke VPNs.
Why it broke Broken and Fixed
Lab complete. Spoke reaches the hub. Overlap is NATed. Isolate Spokes stays On.
Fabric up, overlap NATedRun: Hub and Spoke · Auto-Scale off · Isolate on · OSPF allow
Fabric path
Site Manager · SD-WANHub site
192.168.50.0/24 · public IP
Online · networks advertised
Spoke AoverlapSTOP
192.168.1.0/24
Overlap · not differentiated
Spoke BoverlapSTOP
192.168.1.0/24
Overlap · not differentiated
Spoke A client
Initiates to hub file server
Remote network unreachable
Fabric status SD-WAN
| Cue | Now | Need |
|---|---|---|
| Topology | Hub and Spoke | Hub and Spoke |
| Auto-Scale and NAT | Off | On |
| Isolate Spokes | On | On |
| Tunnel | Active | Active |
| Routes | Missing | Installed |
| Spoke to hub resource | Fail | OK |
| Spoke to spoke | Blocked | Blocked |
Overlapping subnets · Auto-Scale Off · hub unreachable
Hub LAN resource
192.168.50.0/24 · file server| Subnet | 192.168.50.0/24 |
|---|---|
| Service | File server |
| Advertised to spokes | On |
| Reach from Spoke A | Fail |
| Spoke to spoke | Isolated |
Legend
- Healthy / reach OK
- Unreachable / overlap conflict
- Tunnel up, routes missing
- Fabric up, overlap NATed
Controls
Site Manager fabrics. Hub networks advertised stay On. Win needs Hub and Spoke, Auto-Scale On, Isolate On.
Preset
Good to know · info only
Out of scope for this lab
Why this fails
Auto-Scale OffOverlapping subnets · Remote network unreachable
Two spokes on 192.168.1.0/24 look identical to the hub. Without Auto-Scale and NAT Spoke VPNs, Site Magic cannot give each spoke a unique translated /24. Turn Auto-Scale On for Hub and Spoke. Keep On unless spokes must talk to each other.
Console words
- Overlapping subnetsBoth spokes advertise 192.168.1.0/24.Showing
- does not support NATOverlaps cannot exist in a Mesh SD-WAN group.Clear
- Remote network unreachableHub LAN resource not reachable from spoke.Showing
- Tunnel active no routesVPN up. OSPF blocked. Routes missing.Clear
- Isolate Off blocks winKeep On for this lab.Clear
- SD-WAN UDP blockedUDP 20100 to 22100 teaching chip. Locked, not required.Clear
- Fabric up overlap NATedHub and Spoke. Auto-Scale On. Isolate On.Clear
Glossary
Core, Labs 01 to 03- Native VLAN
- The untagged VLAN on a switch port. UniFi device management usually rides here. Set as Native VLAN in Port Manager.
- Tagged VLAN Management
- Port setting for which VLANs ride tagged (802.1Q): Allow All, Block All, or Custom. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
- Access port
- One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
- Trunk
- A port carrying the Native VLAN plus tagged VLANs. The right setup from switch to AP, or switch to gateway, when there are several networks.
- ZBF
- Zone-Based Firewall. Rules are set between zones, like Internal, External, Gateway and Hotspot, plus custom zones such as IoT.
- Gateway zone
- The router itself, which answers DHCP and DNS. Block a network's zone from the Gateway and its clients get no IP or DNS.
- Client isolation
- WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
- PoE class
- AF (about 15W), AT (about 30W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
- PoE budget
- Every device's max draw added up, compared with what the switch or injector can supply. Go over it and devices lose power.
- Injector
- A box that adds PoE power to a cable. Too weak a class, like an AF injector on a loaded Flex, is a common field mistake.
- Max draw
- The most watts a device can pull, from its datasheet (IR on, at boot). UniFi PoE budgets use this, not the quieter live reading.
- Flex budget
- USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
- Remote Unlock via Endpoint
- Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
- Door Attendant / receiver
- User assigned to get the door call. Not on the list means no Unlock for that door.
- Inform
- Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
- STUN
- UDP 3478 helper for remote adoption and remote management. Not the adoption path itself: adoption needs TCP 8080 to the Network host.
- set-inform
- Device SSH command that tells a UniFi device where its Network host is, e.g. http://192.168.1.10:8080/inform.
- Pending Adoption
- Devices list state for a device that has checked in and is waiting for you to click Adopt.
- Managed by Other
- Devices list state. Another instance of UniFi Network owns the device, including the same console after a factory restore. Fix: restore a backup, factory reset and re-adopt, or reassign in the mobile app.
- Device SSH Settings
- Network setting holding the SSH login an adopted device uses. Factory default devices use ui / ui.
- Debug Console
- Built-in browser shell on the console.
- DHCP Option 43
- DHCP option that hands devices the Network host address so they adopt across VLANs.
Fiber terms, glossary ready for later
MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.
Symptom words (overlay language)
Before and after
Diff rows marked| Setting or symptom | Broken start | Now |
|---|
Gear in this lab
- 1 Hub gateway (public IP)
- 2 Spoke gateways (A + B)
- 1 Spoke client
- 1 Hub LAN resource
Config / Site Manager only. Counts only, no prices.
Takeaway
Hub and Spoke NATs the overlap. Keep Isolate on.
Two sites on the same 192.168.1.0/24 cannot share routes until Hub and Spoke turns Auto-Scale and NAT Spoke VPNs On. has no NAT for overlaps. keeps spoke to spoke blocked at the hub while spoke clients still reach hub LAN resources.
- Set Deployment type to Hub and Spoke (not Mesh).
- Turn Auto-Scale and NAT Spoke VPNs On so each spoke gets a unique translated /24.
- Keep Isolate Spokes On unless spokes must talk to each other.
- Confirm OSPF / VPN to Gateway so remote routes install when the tunnel looks up.
Want multi-site UniFi SD-WAN designed for overlapping branches? We plan that as part of a UniFi install.
Related labs
All labs /labs
Auto-Scale and NAT Spoke VPNs
Isolate Spokes
A teaching lab, not a quote and not a design for your site. Settings are simplified from the UniFi Network app and Site Manager. No account, and nothing from this lab is saved.