This short table covers frequently investigated management services. It is deliberately not an instruction to expose every port to the internet. Use the deployment's actual listener and Ubiquiti's full requirements for optional applications, guest portals and remote management.
Common management flows #
| Service | Transport / destination port | Endpoint context |
|---|---|---|
| Device-to-Network communication | TCP 8080 | Managed device reaches Network host |
| STUN | UDP 3478 | Relevant device/remote-management communication |
| HTTPS management | TCP 443 or deployment-specific 8443 | Authorized browser reaches the configured management listener |
| Device discovery | UDP 10001 | Adoption/discovery context; not a substitute for routed reachability |
| SSH | TCP 22 | Authorized administrator reaches the device |
| DNS | UDP/TCP 53 | Device or host reaches its configured resolver |
| Time synchronization | UDP 123 | Device or host reaches its NTP service |
“Ingress” in a vendor server table describes traffic entering that server. It does not mean every upstream firewall should accept unsolicited traffic from any source. Translate the entry into your own diagram, including the actual initiating endpoint and the return traffic allowed by a stateful firewall.
Check the service you actually need #
From an authorized Windows management workstation, a TCP test can help distinguish basic reachability from application behavior:
Check the service you actually need
UniFi · Windows PowerShell
Replace these example values: <network-host>.
Test-NetConnection <network-host> -Port 8080Replace these example values: <management-host>.
Test-NetConnection <management-host> -Port 443A successful TCP handshake confirms a listener was reachable from that workstation. It does not prove the AP can reach it from another VLAN, nor does it validate adoption, credentials or certificate trust. These TCP tests also do not test STUN, DNS over UDP or broadcast discovery.
For a failed adoption, test from the device's management network and correlate with the existing adoption guide. For a browser failure, test the actual management URL and destination port. Do not change the inform destination simply because HTTPS is working: the services have distinct jobs.
Document each required exception as an explicit flow: management VLAN to Network host on TCP 8080, for example. Restrict administrator-only services to the intended management path. A server's internal database port is not a reason to publish its database to managed devices or the internet. If only one optional feature is failing, check that feature's requirements rather than widening the entire ruleset.
Sources
Documentation reviewed: 8 October 2026