MikroTik remote management without a public IP: WebFig and Winbox from anywhere
Last updated: 11 October 2026
Most customer and branch routers sit behind the provider's NAT: no public IP, no way to forward a port, so Winbox from the office is impossible. RadiusNest turns that around. Every router connected to it already keeps an encrypted link to the RadiusNest cloud, and remote management rides on that link: WebFig opens in your browser and Winbox connects from your computer, from anywhere, with nothing opened on the router.
Why the usual ways fail
- No public IP (CGNAT). The WAN address starts with 100.64-100.127, 10. or 192.168. and the provider will not forward ports. IP Cloud gives you a name, but nothing can reach it.
- A changing address on a mobile or home line: it works today and not tomorrow.
- Open Winbox port. Forwarding 8291 to the internet works until the router is found by a scanner. Safe remote access explains what that takes to do properly, and it still needs a public IP.
How RadiusNest remote management works
The router connects out to RadiusNest when you paste the setup script - that is how RADIUS logins reach it. Remote management uses the same encrypted link in the other direction, only when you ask for it:
- WebFig in the browser. Press Open WebFig on the router's page and the router's own web interface opens in a new tab under a RadiusNest address. Pages are passed through to the router as they are; RadiusNest stores nothing. The session ends after two hours, after 30 minutes without use, or when you close it.
- Winbox from your computer. Press Open Winbox and RadiusNest opens a port on its own server that forwards to the router's Winbox. The card shows the address to type into Winbox (
server:port). Only your address may use it, and it closes after two hours. - Your router login stays yours. Nothing is added to the router except one firewall rule that lets the RadiusNest server reach its web and Winbox ports over the link. No user is created, no password changes; WebFig and Winbox ask for your own router user name and password as always.
Set it up (once per router)
- Open Routers in the dashboard and pick the router. The router must be connected (the setup script pasted).
- Open the Remote management tile and press Turn on.
- Press Router script → Copy script, and paste it in the router's terminal (Winbox → New Terminal, or WebFig → Terminal). It turns on the
wwwandwinboxservices and adds one accept rule at the top of the input chain, with the commentRadiusNest-remote. Running it again is safe. - If you moved the router's web or Winbox port, set them under Ports; the defaults are 80 and 8291.
Use WebFig
- Press Open WebFig. A new tab opens with the RouterOS login page.
- Log in with the router's user name and password. Everything in WebFig works: Quick Set, interfaces, firewall, queues, the terminal, files.
- Back on the dashboard the card shows the session as open; Close session ends it at once.
The WebFig tab is tied to the connection that opened it: a copied link or cookie is useless from anywhere else.
Use Winbox
- Press Open Winbox. The card shows an address such as
203.0.113.10:28004. Press Copy address. - In Winbox, paste it into Connect To, type the router's user name and password, press Connect.
- When you are done, press Close port, or let it close by itself after two hours.
Winbox says "the remote host closed the connection"
The port lets in only the address your browser came from. Some providers send the browser and Winbox out through different public addresses, so Winbox is refused. The card then lists the refused address with an Allow button - press it and connect again. On a network that changes addresses all the time, press Allow from anywhere: the port then takes any address until it closes, and the router's own login still protects it.
Also check, on the router, that the rule is there and first:
/ip firewall filter print where comment="RadiusNest-remote"What keeps it safe
- Nothing is opened on the router's internet side. The accept rule only matches the RadiusNest server's address on the encrypted link.
- Only the ISP owner's login on the dashboard can open WebFig or Winbox; team logins and resellers cannot. Every open, close and allowed address is written to the activity log.
- Sessions and ports are short-lived and bound to your address. "Allow from anywhere" is your choice, per port, and ends with the port.
- Turn remote management off for a router at any time; open sessions and ports close with it.
Managing the router from the dashboard without WebFig
For everyday work you may not need WebFig at all: the Live view shows CPU, memory, interfaces and who is online, Router check finds and fixes the settings that stop customers logging in, and users, packages and vouchers are managed in the dashboard and enforced on the router.
Where RadiusNest fits
Remote management is part of every RadiusNest plan, including the free trial. Connect a router, turn the tile on, and manage it from wherever you are - no public IP, no port forwarding, no extra software.
Start the free trial See pricing
Questions and answers
Can I use Winbox on a MikroTik behind CGNAT?
Yes. With RadiusNest the router keeps an outgoing encrypted link to the cloud, and Winbox connects to a short-lived port on the RadiusNest server that forwards to the router over that link. No public IP or port forwarding is needed.
Does RadiusNest see my router password?
WebFig pages are passed through to the router and the Winbox connection is forwarded as it is; nothing is stored. RadiusNest never creates a user or changes a password on the router.
Does it work on RouterOS 6 and 7?
Yes. The router script uses commands that exist in both. WebFig looks different between versions because it is the router's own interface.
Can my staff use it?
No. Only the ISP owner login can open WebFig or Winbox for a router. Team members manage users, vouchers and sessions in the dashboard without reaching the router itself.
Why is Winbox refused while WebFig works?
Your provider sends Winbox out through a different public address than your browser. Press the Allow button for the refused address shown on the card, or Allow from anywhere.