Recognizing CGNAT
A private WAN address or one inside 100.64.0.0/10 is a common indication. A difference between WAN and observed public addresses can also reveal upstream NAT.
Work around the lack of a public address
CGNAT shares a public address among many subscribers and normally blocks incoming connections to your router. Port forwarding on the local gateway is therefore insufficient; the MikroTik must initiate a tunnel to a reachable service.
A private WAN address or one inside 100.64.0.0/10 is a common indication. A difference between WAN and observed public addresses can also reveal upstream NAT.
The connection starts from the customer network, like ordinary web traffic. The remote service then carries only authorized administration flows through that tunnel.
Remote access without an ISP public-IP option
Compatible with many 4G connections
No inbound port required on the gateway
Controlled and revocable remote endpoint
Compare the WAN address with the observed public address.
Create a persistent outbound tunnel to SunVPN.
Test WinBox and restrict services to the tunnel interface.
No when the operator also performs NAT upstream of your gateway.
Yes, it is common on 4G and some fixed connections.
Not necessarily. An outbound tunnel can provide remote access without that ISP option.
Create your SunVPN account and configure your first connection in a few steps.
Démarrer maintenant