Configure MikroTik RB960PGS for Plug-and-Play Camera Setup with AWS VPN

Job ID: 39287047

Budget: $750 – $1,500 AUD

We need an expert to configure a MikroTik RB960PGS router and set up an AWS-hosted VPN server for a surveillance camera deployment project. The goal is a pre-configured, plug-and-play solution for PTZ and bullet cameras at various residential and commercial sites with different internet types (NBN, ADSL, Starlink, 4G) and existing setups (home routers or commercial CCTV systems). The RB960PGS should power cameras via PoE, connect to the internet, and provide secure remote access via VPN without requiring port forwarding.

Tasks:

1. RB960PGS Configuration:
- Set Ether1 as WAN (auto-grabs IP from any Ethernet uplink).
- Set Ether2-5 as a PoE LAN switch with DHCP for cameras (e.g., 192.168.x.100-200).
- Add a script/menu for me to choose the LAN subnet on-site (e.g., options: 192.168.1.0/24, 192.168.2.0/24, 192.168.3.0/24, or custom input) to avoid conflicts with local networks. Default to 192.168.2.0/24 if unchanged.
- Install an OpenVPN or WireGuard client to auto-connect to the AWS VPN server.
- Configure NAT and a basic firewall to secure the LAN and allow VPN traffic while blocking unwanted access.
- Ensure plug-and-play: works when plugged into any router/modem with Ethernet.

2. AWS VPN Server Setup:
- Deploy an EC2 instance with OpenVPN or WireGuard.
- Configure unique VPN credentials for each RB960PGS (scalable for multiple sites).
- Route traffic so I can remotely access each site’s cameras (e.g., via private subnets like 10.0.x.x).
- Ensure compatibility with CGNAT (e.g., Starlink, 4G).

3. Testing & Documentation:
- Test the setup with a dummy router and camera to confirm VPN, PoE, NAT/firewall, and remote access work.
- Provide simple instructions (or a short video) for me to:
- Check the local subnet (e.g., via ipconfig).
- Log into the RB960PGS and pick a subnet via the script/menu.

Requirements:
- Experience with MikroTik RouterOS, AWS EC2, and VPNs (OpenVPN/WireGuard).
- Deliver a script for the RB960PGS and VPN server config files.
- Solution must be scalable and easy for a non-expert to deploy on-site with minimal setup (laptop for subnet selection only if needed).