Looking for VPN provider suggestion - with PortFWD

Hi guys,

Hope this is the right category to ask
I’m looking for and advice about some good 3rd party VPN provider with such Prerequisites:

  • Port Forwarding
  • WireGuard would be great
  • Router level VPN setup, not using app (rarely on mobile when travelling…)
  • Some good guide how to setup on Miktotik would be awesome as not usually that simple :wink:

There are many on market , but only few has PortFWD which could be setup directly on Router, not only on their Win/Android app.
I’ve been using AzireVPN for few years, but they changed their Port Forward policy and now I need to re-add the port each month. Even since i’ve moved to Mikrotik routers, wasnt been really able to make PortFWD working.

Thanks!

tailscale

Purpose: If its to use internet from a different location there are many that offer wireguard.
Purpose: If its for external users to reach your router by using public IP address of a router in a different location, not aware of any… ( did you consider zerotier ??)
(you could rent your own cloud server for this for about $7 plus buy CHR MT license.

Tailscale - did have a look the lowest is FREE, thats good.
Seems like I’m not really clear how this VPN works and if it can do Port Forwarding the way as former VPN (OpenVPN, WG) did.

Purpose: If its to use internet from a different location there are many that offer wireguard.
Yes , as i do not have Public IP (i’m behind some NAT from provided, with shared IP)
I do need Port Forward or some VPN Public IP (was possible via AzireVPN in the past, before they changed)
So I can:

  • access some Servers/Dockers on my NAS
  • had duckdns Docker setup an via xxx.duckdns.org i was able to use my services from Internet
  • DC++/Torrent be an “Active” user

Hope my request is clearer now.

In the background im doing research and asking various VPN providers how they work via Router setup, as many have no clear explanation about it. Mostly just app win/mobile instructions for regular users.
Some are still only on OpenVPN (with port fwd) and they have WG (without portfwd). Where as I understand OpenVPN has slower speeds and possibly less secure vs WireGuard

I would look at
a. zerotier as its available in RoS for any networking things you want to do… ( basically puts all joined entities into a layer2 construct together )
b. BTH VPN this would be used for you to remotely configure the router from any device externally ( smartphone, laptop etc…).

My preference would be to use zerotier for the LAN work and BTH to configure the router.
It would also be perfectly feasible to use Zerotier for both, but BTH doesnt rely on third party to access the router ( other than MT relay server ) and thus a bit more secure.
However, BTH does rely on MT server and that has been known to go down a couple of times per year.

Lastly, to accomplish both, buy a chr license and rent a cloud server and accomplish both tasks.
However zerotier is IMHO a safer way to access your router…as port forwarding regardless of how it travels to get there, is a relatively open door to your router…
Tis why I have requested and begged MT to make zerotrust cloudflare also an option for ROS and this is designed specifically to make port forwarding secure and easy.

@anav seems like you were helping me here also :wink: http://forum.mikrotik.com/t/wireguard-azirevpn-misbehavior/165351/39

Lot of shortcut words, but seems I’ve manage to find it…

  1. I just installed Mikrotik “Back to home” app seems to be working, didnt knew about it…
    If I understand it right , it’s some MT’s Free secure VPN tunnel to access Mikrotik router and it’s settings?
  • also meant to access Local Network and its services?
    If so finally my local NextCloud server (for photos) will be available also remotely, yeayyy :open_mouth: :slight_smile:

This should cover most of the Services from NAS which I wanted to connect to

  1. Zerotier - will take some time to read and understand all , seems pretty new feature https://help.mikrotik.com/docs/spaces/ROS/pages/83755083/ZeroTier
    Created account - done

So via Zerotier I should be able to configure access from Internet to my Docker or Server via XXXX port?
Eg. eventually become P2P Active user share?

Does is give also privacy/anonymous layer as regular “Private VPN” services?

Thanks

Someone else will have to answer your zerotier questions as I have little experience.

Looking at your diagram from the other thread, it would appear you are stuck with switches that dont provide guaranteed vlan performance.
Suggest a pair of hex refreshes are decent cheap managed switches…

Here is my result:
Zerotier seems not to have PortForwarding (or havent found how) to access my local hosted services from internet via IP,DDNS or similar…

Mikrotik’s Back to Home VPN - when I enable / installed on Android afterwards connected , I was able to connect only to my MK router, but rest internet just stopped working (during the time connection was enabled), couldn’t even connect to my other local hosted services/servers. No clue what is the problem, but seems like not out of the box working solution.
Didnt had time yet to investigate further.

So I purchased 1month try of AirVPN and new issues :smiley:
http://forum.mikrotik.com/t/req-airvpn-wireguard-fine-tune-assistance/181278/1

@anav Could you please have a look in here? http://forum.mikrotik.com/t/req-airvpn-wireguard-fine-tune-assistance/181278/2
As my “regular” internet is smooth all good, but soon as I connect to VPN via WG it seems to have some sort of DNS issues/lags. Some time ago you were able to help out with my former VPN setup, now I’m struggling again :frowning:

Thanks

So via Zerotier I should be able to configure access from Internet to my Docker or Server via XXXX port?
Eg. eventually become P2P Active user share?

Total beginner with Zerotier , while looking for a P2P VPN service. Most public VPN services seem to have dropped their P2P or port-forwarding support recently.
The service to surf the internet via a VPN is everywhere (Tailscale, Surfshark, NordVPN and many others. Some travel-routers support 30 VPN providers)

P2P capable list for my devices so far is limited. Looking at Zerotier, Tailscale, Surfshark, SoftEther, Neorouter …).
But actually I had build my own, with a hAP Lite as HUB , with just one port reachable via Internet (with the needed port forwards, in multi NATted environment, but that HUB is a router-on-a-stick setup.
My static HEXes and travel mAP Lites connect via all sorts of load-balanced and heavy NATted visited and managed networks.
Just a decent IP-plan is needed for the HUB routing and SRCNAT (to eliminate local return route settings).

BTH is one P2P service, well BTH is Wireguard ending in a MT router, making that router an exit node is easy MT work.

So I hope this can also work with Zerotier, as we can define the routes for our local subnets in https://my.zerotier.com/network

Managed Routes
IPv4 and IPv6 routes to be published to network members. This can be used to create routes to other networks via gateways on a ZeroTier network. Note that for security reasons most clients will not use default routes or routes that overlap with public IP address space unless this is specifically allowed by the user. Public IP ranges are marked with an icon:.

Maybe some more to test here: nice overview on VPN setup with Mikrotik.: https://www.vpn.com/device/router/mikrotik/

http://forum.mikrotik.com/t/propose-mikrotik-to-adopt-tailscale-vpn-similar-to-zerotierone-vpn/153382/1 MikriTik forum Propose Mikrotik to adopt TailScale VPN similar to ZeroTierOne VPN
https://github.com/Fluent-networks/tailscale-mikrotik GitHub project Tailscale for Mikrotik Container
Nothing above is a recommendation; just adding TailScale information.