Browser-based MikroTik administration

Open Webfig remotely and securely

Webfig lets you manage RouterOS from a browser, but direct public exposure greatly increases risk. The safer method is to make it available only through a VPN tunnel or an authenticated proxy.

Why direct exposure is risky

A public Webfig port can be scanned and attacked. A tunnel reduces the visible surface and reserves the interface for authorized users.

HTTPS is still necessary

The VPN protects transport, while HTTPS adds another layer and a service identity. Avoid plain HTTP for administration sessions.

What you get

Administration without installing WinBox

Access from a computer or mobile device

Service isolated behind the tunnel

Central revocation of remote access

How it works

  1. 1

    Enable HTTPS and install a valid certificate.

  2. 2

    Restrict Webfig to tunnel addresses.

  3. 3

    Test external access and review RouterOS logs.

Frequently asked questions

Does Webfig work on mobile?

Yes, it is available through a compatible web browser.

Can the Webfig port be changed?

Yes, but changing a port does not replace a tunnel or firewall.

Should Webfig remain available on WAN?

No. Restrict it to the VPN or tightly controlled administration addresses.

Ready to manage your MikroTik remotely?

Create your SunVPN account and configure your first connection in a few steps.

Démarrer maintenant