I wanted my remote routers to feel like they were sitting next to me

One of the most annoying things about managing remote MikroTik routers is realizing that the router you're trying to reach is sitting behind CGNAT.

No public IP.

No port forwarding.

No easy way to just open WinBox and connect.

And when you start doing this across multiple sites, things get messy quickly. Every site becomes its own little networking problem.

I wanted to get away from that.

So the idea became:

What if I could just connect my laptop to one private network and reach every router as if I were physically there?

10 routers.

10 different locations.

Different ISPs.

Some behind CGNAT.

Each router makes an outbound connection to TunGuard.

Once they're connected, I don't care where the router physically is anymore.

I just use its private tunnel IP:

WinBox β†’ 10.100.x.x SSH β†’ 10.100.x.x API β†’ 10.100.x.x

Even the SSH jump host is there when I need it.

And the same network can connect sites to each other.

That's the part I really like.

I don't have to think about the physical location anymore.

The router could be across town, in another building, or behind CGNAT on some random ISP.

From my laptop, it just feels like:

another device on my network.

That's the experience I wanted TunGuard to provide:

remote infrastructure that feels local.

TunGuard is open source. Search for TunGuard on GitHub, grab the latest tanguard-binary release, and try it yourself.

Tailscale, Zerotier, Netbird...

Yep, I know Tailscale and ZeroTier :grinning_face_with_smiling_eyes:. TunGuard is aimed at a different setup: self-hosted, WireGuard-based, and focused on managing routers/sites where I control the whole infrastructure.

ipsec (or other VPN) from behind the CGNAT to you, and tell all the 3rd parties with thier hands out for $$$ to go away . . . (If your local network is that crippled, FIX IT!)

Back-to-home? If you have one ARM or X86, that an option. You would need to delegate one as the master, and then create users that are actually routers so you just import the wg config from the master with back to home enabled. You can layer on EoIP using the BTH address to connect the EoIP tunnels and you can use the EoIP in some VLAN bridge if you want since EoIP creates "ethernet-like" interfaces over the WG peers created by BTH.

What is the benefit over using a ROS device as wireguard "server"? You add one peer configuration for each device you manage, configure wireguard peer on remote device. What is the difference? The GUI?

That's a fair question. If you only have a few routers, a MikroTik WireGuard server works perfectly fine. The difference I'm focusing on is provisioning and management at scale. With TunGuard, I can generate the RouterOS provisioning script, run it on a remote router, and it automatically joins the network. The same tunnel then gives me WinBox/SSH/API access. So it's less about WireGuard itself and more about removing the repetitive configuration when you're managing many sites.

Will you stop opening more posts about the same thing?

Seems like software "solution" that's looking for a problem to solve and he's just blatantly advertising on the forum, but i guess the forum is called 3rd party tools, so you cant really say anything about it...

Indeed. @Tunguard already created several other topics in the "3rd party tools" section. Please stop doing that. One topic is enough. Thanks.

We use the Tik-Own BTH "Back-To-Home"-VPN which initiates an outbound connection to Tiks-relay-servers (WireGuard under the hood). You can connect from the public WAN to the relay-address and from there you will be routed to the "behind-CGNAT"-device.

I was suggesting here they should separate this CGNAT-relay-stuff from the rest of BTH (like the built-in-user thing) for professional use. But the interest was very low. For us a nice thing to use without stuff like Tailscale, Zerotier...

@Guscht don't waste your time, they don't care what you write,
they only care about being indexed on Google, don't fall for this bllsht...

??? Who? Tik? The Latvian-Swamp-Nerds care about their Google-Index o_O

no, the @Tunguard

Yes, the OP, not MikroTik :rofl:

Of course we do care ......what we don't care about is why should I struggle to make things works.....we don't want to prove a point we want to make our connection just easy so rextended just extended your issue somewhere else anyway I am sick of your critics you never even used TunGuard yet you speak boss language as if you are the only guy who understand mikrotik

I hope it doesn't affect you either it's mikrotik community other. People maight find it ..on use if you find it bs then don't contribute on the threads nobody needs your contribution :-1: FYI

Yeah you are begging for attention here just go somewhere else please... nobody cares about your op

Closing the topic which is created just to make click-bite buzz and the "3rd party tools" is not the proper category for the problem you raised/advertise.

@Tunegard
Please publish "news" on yor solution in the original topic Managing MikroTik Routers Behind CGNAT Using TunGuard (Userspace WireGuard VPN)

No need to discuss artificialy created problems that are not solved by your solution in any special way. Just "the other way". Suggest creating your own www page/forum or any medium where you can advertise your product again and again.

New topics about your package would be merged into the original thread.