RadiusNest › Guides

MikroTik remote access: reach Winbox from outside, safely

Last updated: 11 October 2026

Managing customers' or branch routers from home saves a lot of travel. Opening Winbox to the whole internet is also how many MikroTik routers get taken over. These are the safe ways to do it, best first.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

Best: Winbox open to your addresses only

If your office has a fixed public address, let only that address in:

/ip firewall address-list add list=admin-ok address=198.51.100.25 comment="office"
/ip firewall filter add chain=input in-interface-list=WAN protocol=tcp dst-port=8291 src-address-list=admin-ok action=accept comment="Winbox from office" place-before=0

Then limit the service itself to the same addresses plus your LAN, so a firewall mistake later does not open it:

/ip service set winbox address=198.51.100.25/32,192.168.88.0/24

Use Safe Mode for this step: if you leave out the address you are connected from, you lock yourself out.

No fixed address: port knocking

If your own address changes, let the router add it to the allowed list when you "knock": a connection attempt to one secret port, then to a second one, within a short time. Anyone who does not know both ports sees nothing.

/ip firewall filter
add chain=input in-interface-list=WAN protocol=tcp dst-port=24561 action=add-src-to-address-list address-list=knock1 address-list-timeout=15s comment="knock 1" place-before=0
add chain=input in-interface-list=WAN protocol=tcp dst-port=37022 src-address-list=knock1 action=add-src-to-address-list address-list=admin-ok address-list-timeout=1h comment="knock 2" place-before=0

Choose your own two port numbers and keep them secret. To get in, open the first port and then the second from your computer, for example by typing http://your-router-name:24561 and then :37022 in a browser (the pages do not load; the attempt is enough). Your address then stays in admin-ok for an hour, and the Winbox rule above lets you in. In this case do not limit /ip service winbox to fixed addresses (leave its address field empty): your address is not known in advance, and the firewall rules do the limiting.

Not enough on its own: another port

/ip service set winbox port=18291

A different port cuts down the automatic scans in your log. It does not stop anyone who scans all ports. Use it as well as one of the methods above, never instead.

Never do this

  • Open Winbox, SSH, Telnet, FTP or the web page to everyone, least of all with a weak or default password.
  • Leave admin as the user name. Make your own admin user and remove or disable admin.
  • Run an old RouterOS version that faces the internet. Several old versions had flaws that let attackers in without a password; upgrade.

Finding the router when its address changes

Use the free IP Cloud name. A router behind CGNAT cannot be reached from outside at all; ask the provider for a public address.

Check who has been knocking

/log print where message~"login failure"
/user active print
/ip firewall address-list print where list=admin-ok

For the full checklist, see how to secure a MikroTik router.

Where RadiusNest fits

Day-to-day work with customers does not need the router at all in RadiusNest: staff and resellers add users, renew packages and print vouchers in the dashboard, and never see the router password. Keep router access for the few people who change its configuration.

Start the free trial See pricing

Questions and answers

Which port does Winbox use?

TCP 8291 by default. You can change it in /ip service.

Is it safe to open Winbox to the internet?

Not to everyone. Allow only your own addresses, or use port knocking, and keep RouterOS up to date.

How do I reach a MikroTik behind CGNAT?

Not from outside: CGNAT blocks every incoming connection. Ask the provider for a public IP address.

Related guides

Start the free trial See pricing