Peplink B One ↔ UniFi Cloud Gateway Ultra (UCG-Ultra) VPN - Tunnel Up but No Routing

Hi all,

I’m hoping to get some guidance on a site-to-site VPN setup I’m working on between a Peplink B One and a UniFi Cloud Gateway Ultra (UCG-Ultra).

Current state:

  • I have an IPsec VPN established between the two devices
  • The tunnel shows as connected/healthy on both sides
  • However, I am not getting any routing between the LANs on either side

What I’ve checked so far:

  • Local and remote subnets appear to be defined correctly on both ends
  • Firewall rules don’t seem to be explicitly blocking traffic
  • NAT settings look reasonable (but I could be missing something subtle)

Where I’m unsure:

  • Is IPsec still the best approach for this type of setup between Peplink and UniFi gear?
  • Would something like another VPN type (OpenVPN, WireGuard, etc.) be more reliable or easier to configure in 2026?
  • Are there any known quirks between Peplink and UniFi when it comes to IPsec routing?

What I’m looking for:

  • Common things to check when the tunnel is up but no traffic passes
  • Recommended configuration patterns for this specific combination of hardware
  • Any tutorials, guides, or example configs that walk through Peplink ↔ UniFi VPN setups

If anyone has this working (especially with a B One and UCG-Ultra), I’d really appreciate any pointers or even screenshots of key settings.

Thanks in advance for any help!