UniFi Lab 03
Access unlock missing on call
They can answer the door call. They cannot unlock. Here is why.
Your job: get Unlock on the Basic phone during a Front Door call, without breaking Admin.
This run: Break A. Front Door, Endpoint receivers.
Lab complete. Basic sees Unlock on the call, and Admin still works.
unlock_availableOn call, Unlock presentTopology
Site: Access lab, Front Door- ConsoleUnlock stops hereUniFi Access applicationRemote Unlock via UniFi Endpoint: OffCall path: Endpoint
- Remote Unlock disabledEndpoint receivers can talk, cannot unlock.
- Door HubFront Door. Lock wiring out of scopeOnline
- AdminReceiver
- BasicNot assigned
- Front Door receivers readyAssigned receivers get the call path.
- Doorbell / intercomPlaces the Front Door callRinging
- Call connectedAudio works on Admin and Basic.
- PhonesAdmin and Basic Endpoint receiversunlock_missing_on_callUnlock not availableremote_unlock_disabledRemote Unlock disabled
Admin Unlock: Missing Basic Unlock: Missing
Legend
- Call and Access path
- Unlock missing on this path
- Up, assigned, or allowed
- Unlock missing or setting off
- Warning, not a win
- Win status
Simulated call
Unlock missing or greyedFront Door is ringing. Talk works on both phones. Unlock depends on the Access settings below.
Unlock not available on this receiver.
Unlock not available on this receiver.
Controls
The Access settings you can change in this lab. Door Hub LOCK NO/NC wiring is out of scope.
Access → Settings → General
- Application
- UniFi Access
- Setting path
- Settings → General
- Door
- Front Door
- Account
- Invited identity
Global. When Off, Endpoint receivers can talk but cannot unlock.
Front Door, call receivers
Adds Basic to Front Door call receivers / Door Attendant.
Simulated call view
Refresh the receiver chrome. Shows Unlock present or absent for the current view.
Out of scope for this lab
Why this fails
copy key: remote_unlock_disabledRemote Unlock via UniFi Endpoint is off
Unlock not available. Remote Unlock disabled
Field note: Talk works. Unlock does not. Access has a global switch: Remote Unlock via UniFi Endpoint. When it is off, Endpoint receivers can converse but cannot unlock. Turn it on, then retest the call.
Fix: Set Remote Unlock via UniFi Endpoint to On in Access → Settings → General.
Console words
- Unlock not availableShowing
- Remote Unlock disabledShowing
- User is not a receiver for this doorClear
- Talk / call connectedShowing
- Unlock on BasicMissing
- Unlock on AdminMissing
Glossary
Core, Labs 01 to 03- Native
- Untagged VLAN on a switch port (PVID). Management traffic usually rides here on UniFi device uplinks.
- Tagged
- VLAN IDs carried with an 802.1Q tag on a trunk. Guest and IoT SSIDs need their VLANs tagged on the AP uplink.
- Access port
- One VLAN only, untagged. Fine for a printer. Wrong for an AP that serves multiple SSIDs.
- Trunk
- Native + tagged VLANs. Correct pattern for UniFi switch to AP / switch to gateway when multiple networks exist.
- ZBF
- Zone-Based Firewall. Policies between zones (Gateway, External, Internal, Guest, etc.), not just classic LAN IN rules.
- Gateway zone
- Where the router answers DHCP and DNS for a network. Block Guest to Gateway and clients get No IP or DNS unreachable.
- Client isolation
- WiFi setting that stops guest clients from talking to each other. Keep on for Guest.
- PoE class
- AF (~15 W), AT (~30 W), BT / PoE++ (higher). UniFi budgets on documented max draw, not quiet daytime watts.
- PoE budget
- Sum of max PD draws vs what the switch or injector can supply. Exceed it and devices disconnect.
- Injector
- Power source for a Flex or similar. Wrong class (AF on a loaded Flex) is a classic field fail.
- Max draw
- Datasheet maximum watts for a PD (IR on, boot). UniFi PoE budget math uses this, not the quiet live reading.
- Flex budget
- USW-Flex downstream totals by input: AF 8W, AT 20W, BT or 60W injector 46W (set Power Source to PoE Injector).
- Remote Unlock via Endpoint
- Access setting. When off, Endpoint receivers can talk on a call but cannot unlock.
- Door Attendant / receiver
- User assigned to get the door call. Not on the list means no Unlock for that door.
- Inform
- Device check-in URL to the Network application, usually controller host on port 8080, path /inform.
- STUN
- UDP 3478 helper for L3 / remote adoption. GUI on 443 is not the same path.
Fiber terms, glossary ready for later
MM and SM grades, cage form factors, DAC, AOC, and complementary BiDi ends. Full rows land with the fiber-sfp-dac lab.
Symptom words (overlay language)
Before and after
Diff rows marked| Setting or symptom | Broken start | Now |
|---|
Gear in this lab
- 1 Console
- 1 Door Hub
- 1 Doorbell / intercom
- 2 Phones (Admin, Basic)
Config only. The fix needs no new hardware. Counts only, no prices.
Takeaway
Talk is not the same as Unlock
When someone can answer the door call but has no Unlock button, the cause is usually Remote Unlock via UniFi Endpoint or receiver assignment, not "Basic users can never unlock."
- Turn on Remote Unlock via UniFi Endpoint in Access → Settings → General.
- Assign the Basic user as a Front Door receiver or Door Attendant.
- Retest the call on the invited account. Unlock should appear for Basic.
- Confirm Admin still unlocks. No regression.
BOM delta on win
Config only. No hardware change. Door Hub LOCK NO/NC wiring is Lab 06.
| Item | Broken start | After fix | Change |
|---|---|---|---|
| Console with UniFi Access | 1 | 1 | No change |
| Door Hub, Front Door | 1 | 1 | No change |
| Doorbell / intercom | 1 | 1 | No change |
| Phone users (Admin, Basic) | 2 | 2 | No change |
Want Access and intercom set up like this at your place? We design UniFi Access and door entry as part of a UniFi install.
A teaching lab, not a quote and not a design for your site. Settings are simplified from UniFi Access. Door Hub LOCK NO/NC wiring is out of scope here.