Access rbsxt behind rb951

Is there a way to access RBSXT AP with ip cloud behind rb951 nat?

I want to be able to configure AP from my house.
I have already access to rb951 router with ip cloud.

You would still need a port forward to access the SXT.

The ‘IP Cloud’ feature is rather grandly named for what pretty much amounts to a canned DDNS service. Perhaps Mikrotik have plans to expand this in future to some sort of cloud management.

I had make a dstnat rule and i have access to rbsxt from my house. I have give ip 192.168.88.2 to rbsxt. The thing is i dont want the ap to have a ip address. Can i make dstnat with mac address for example?

A ‘port’ is a layer 4 concept, and for it to be any use, you need a layer 3 [IP] address. The closest you’re going to get to what you’re asking for is to access your RB951 with L3 management [ie SSH to it] and from there use the L2 managment tools to access the SXT [ie /tool mac-telnet].

the problem is i want to use winbox to make settings to rbsxt. i am not very comfortable with telnet!

Make port redirection on the natting device. Than you can access it with winbox easily.

If you really, really, really don’t want to have an IP on the RBSXT and you want to use Winbox, you could create a L2 tunnel [eg EoIP] between where you are and your RB951, that way you can access the RBSXT with L2 management. Otherwise, RBSXT will have to have IP address to use a port forward for management.

This sounds like RoMon might be the new answer…

It’s too early to talk about romon now. I am proud that romon looks to be an answer to my request rised some years ago (probably I was not alone), but it is still not enough proved. Actually I was not able to test it yet as with 6.28 I went into winbox3rc9 crashing problem. So the question is which further combination of ros and winbox will allow to try it. On the other side the natting and routing rules are enough so far to get access whenever I need to. And I am a bit afraid that romon could open another attack vector to the router itself…

You are not alone in that fear. . .

I’m about to start messing around with it myself…

the RBSXT is appearing in my dhcp list as it has dhcp client enable.
i am using a simple QUEUE to equally share bandwidth to my clients network 192.168.88.0/24
does this also apply to SBSXT that it has ip 192.168.88.11 ?
how can i exclude the AP from simple queue?

romon is a nice feature to access devices behind rb router.
but after i upgrade all to 6.29 i connect to romon router (rb951) and when i try to connect to my rbsxt i get a message “disconnected from romon” in winbox.