I have recently installed a Ubiquiti Cloud Gateway Ultra, along with a number of AP's.
I would like to use the Ubiquiti Teleport VPN on my mobile, to allow me to access my home network and specifically HA via the iPhone app when I'm away from the house.
Firstly, is this possible?
Assuming it is, is it also possible to configure the mobile app to connect via the VPN automatically, so I wouldn't have to first start the VPN back to home and then launch HA?
I don't use Apple products, but Teleport has worked on Android. The issue is the process is manual, and the process of Teleport connecting can take several seconds. I've also seen Teleport break for no apparent reason for whole firmware releases (and there's not much debug info).
The VPN is under the control of iOS and the Ubiquiti app, so I doubt HA can change any settings and it may only see a LAN IPv4 (which you may need to set up manually as mDNS is probably not VPN routable - I used to use static). You could leave the VPN on all the time, but the additional network latency and MTU limits aren't ideal.
A friend could never connect to my HA instance from iOS, and complained at my network. The problem? He'd neglected to mention he'd installed a VPN, so all the LAN traffic disappeared to the WAN.
The Nabu Casa service "just works", and switches from LAN to WAN automatically.
The teleport is just another VPN. Given that, yes it will work as you wish.
As for have it automatically...
Teleport and most. Other VPN solutions support split tunneling which direct your VPN destined data down the tunnel as necessary and direct Gen internet traffic down the main pipe. Turn this on and don't worry about It anymore home traffic goes home.
Not that I am aware of. I manually connect to Teleport (via the WiFiman app) only when I need to access my home network. I use a domain and a reverse proxy to make HA available to the outside world without a VPN. But Nabu Casa is the easier method to do this.
I am not aware of a split tunneling feature available for Teleport. Do you have any detail on this?
I’ve not tried pcap and route tracing, but my experience (and that of a friend on an iPhone) suggests Teleport is not doing split tunnelling WAN/LAN much as that would be useful.
As Teleport is really just wireguard with training wheels (Tailscale-ish?), the tech may allow split, but it was hard enough getting Teleport working at all.
I never managed to get WireGuard working from Linux to a UDM, so am stuck with WiFiman on Android.
It’s under the identity section (because that makes soo much sense) and it’s is exactly wire guard with training wheels. I’ll find it when I get home from work. If yih just need tk define one subnet it’s fine.