MikroTik CHR VPN Setup
Budget: $30 – $250 USD
I have a cloud-hosted MikroTik CHR with a public IP and I want it to act as the central SSTP VPN hub for more than ten remote MikroTik routers that sit behind NAT and have no public addresses.
Here is what I need done:
• Enable and properly secure an SSTP server on the CHR. I want simple username-and-password authentication only—no certificates.
• Prepare a template configuration that each remote router can import so it dials the CHR automatically, comes up on a dedicated tunnel, and registers in a way that makes future scaling easy.
• Set up routing, firewall, and NAT rules so that from my workstation I can open Winbox (port 8291) or the API (port 8728) on any remote router by using the CHR’s public IP followed by a unique external port you assign.
• Document the port mapping scheme so I always know which external port corresponds to which remote router.
• Test the solution with at least one remote MikroTik to confirm:
– SSTP tunnel establishes and stays stable
– I can reach Winbox and API through the forwarded ports
– No traffic leaks outside the tunnel
Deliverables:
1. Export/backup of the final CHR configuration.
2. Step-by-step notes or script for provisioning additional remote routers.
3. Quick hand-off call or chat to walk through the setup and verify everything works.
RouterOS experience with SSTP, NAT, and firewall rules is essential; please mention any similar deployments you have completed.
Here is what I need done:
• Enable and properly secure an SSTP server on the CHR. I want simple username-and-password authentication only—no certificates.
• Prepare a template configuration that each remote router can import so it dials the CHR automatically, comes up on a dedicated tunnel, and registers in a way that makes future scaling easy.
• Set up routing, firewall, and NAT rules so that from my workstation I can open Winbox (port 8291) or the API (port 8728) on any remote router by using the CHR’s public IP followed by a unique external port you assign.
• Document the port mapping scheme so I always know which external port corresponds to which remote router.
• Test the solution with at least one remote MikroTik to confirm:
– SSTP tunnel establishes and stays stable
– I can reach Winbox and API through the forwarded ports
– No traffic leaks outside the tunnel
Deliverables:
1. Export/backup of the final CHR configuration.
2. Step-by-step notes or script for provisioning additional remote routers.
3. Quick hand-off call or chat to walk through the setup and verify everything works.
RouterOS experience with SSTP, NAT, and firewall rules is essential; please mention any similar deployments you have completed.
Related categories:
System Admin
Linux
Cloud Computing
Cisco
Network Administration
Network Security
VPN
Firewall