Work around the lack of a public address

Make a MikroTik reachable behind CGNAT

CGNAT shares a public address among many subscribers and normally blocks incoming connections to your router. Port forwarding on the local gateway is therefore insufficient; the MikroTik must initiate a tunnel to a reachable service.

Recognizing CGNAT

A private WAN address or one inside 100.64.0.0/10 is a common indication. A difference between WAN and observed public addresses can also reveal upstream NAT.

Why the tunnel works

The connection starts from the customer network, like ordinary web traffic. The remote service then carries only authorized administration flows through that tunnel.

What you get

Remote access without an ISP public-IP option

Compatible with many 4G connections

No inbound port required on the gateway

Controlled and revocable remote endpoint

How it works

  1. 1

    Compare the WAN address with the observed public address.

  2. 2

    Create a persistent outbound tunnel to SunVPN.

  3. 3

    Test WinBox and restrict services to the tunnel interface.

Frequently asked questions

Is gateway port forwarding enough?

No when the operator also performs NAT upstream of your gateway.

Is CGNAT used on mobile networks?

Yes, it is common on 4G and some fixed connections.

Must I buy a public IP?

Not necessarily. An outbound tunnel can provide remote access without that ISP option.

Ready to manage your MikroTik remotely?

Create your SunVPN account and configure your first connection in a few steps.

Démarrer maintenant