At the moment, administrators who use restrictive firewalls or allowlists may not know which destinations must be permitted in order for Back to Home sessions to establish successfully. Could MikroTik provide the following information in the current documentation?
The FQDNs and IP addresses of all available Back to Home relay servers
The required protocols and ports
Whether IPv4 and IPv6 endpoints are available
Any regional or fallback relays
How often the list may change
A recommended method for obtaining the current list automatically
It would also be helpful to include this information in the Back to Home documentation, alongside the list of addresses that must be allowed for MikroTik device management through MikroTik Cloud—for example, the endpoints associated with cloud2.mikrotik.com like this Communication with MikroTik Cloud/Servers - RouterOS - MikroTik Documentation
Having a single official source for both Back to Home relay destinations and MikroTik Cloud management endpoints would make it much easier to configure firewall rules and allowlists correctly, particularly in enterprise and highly restricted networks.
Would it be possible for MikroTik to publish and maintain this list?
Well, I wouldn't use any third-party services...
Your request is strange... It doesn't make sense...
If I had to be sure, I'd implement everything on my devices, with specific IP addresses, etc.
I certainly wouldn't use MikroTik relays...
What you're saying just doesn't make sense to me... Is only suspicious.
Except for one thing, MT did state that they would have a number of relays that would be more or less geographically pertinent to a persons location. It would be useful to know, perhaps if travelling, which BTH server to use etc. Not sure but maybe the servers they use, automatically adjust for location?
There's no need to be suspicious... In the enterprise environment, people certainly use their own systems. But that doesn't mean they want to test a product. Why is this suspicious?
If you look at e.g. the WinBox menu for BTH, the pings for the different BTH relays are displayed, so the choice is probably made on the router itself.
I think the easiest way to publish a list of relay addresses would be a simply DNS entry, like bth-relays.mikrotik.com, that can then easily be used in address lists...
I am suspicious by nature, otherwise I wouldn't be myself.
Supposed security doesn't go unnoticed with a third-party service
(as secure as it is, I'm not questioning MikroTik... otherwise, I wouldn't even use its software).
And if I do run tests, I'd never do them within the company network,
but separately,
where even if I connect a super-infected computer, it doesn't affect everything else...
I understand your point and agree with your thinking..But sometimes it's important to have this information to be able to ask for the right openings.Furthermore, it is also important to understand that in some cases this information is used to protect your systems and avoid this. It is better to know your enemy and not pretend not to know he exists.
I didn't understand, if this is the complete list of relays or they are an extract of the "fastest" ones that the system would like to use... In addition to the "VPN Preferred Relay Code" option, I can indicate any relay (and if there is a complete list) Or are the only 2 relays available (at the moment) these indicated on the screen?
Well... I fully expected to write that currently this seems to be the full list.
The usual way to implement this on the networking side is to have "servers" instead of servers, where each published ip has multiple physical (or virtual) machines behind it, and routing is done with some type of ECMP.
It seems to not be so with Mikrotik BTH. For me, on a different device, the same list that you posted shows the same addresses with x.y.z.98, so a different last octet.
Maybe this is derived from the S/N? DNS round-robin? Anyhow, currently the full list seems kind of hard to get...
It's a reasonable request IMO. Whether you want to block it in larger network, or perhaps prioritize it in queues... knowing the list of servers (or at least the DNS names used) would be helpful.
I'd still like to be able to run your own relay server (part of what I've long asked for, some "BackToWork") - since the scheme is solid IMO. But the vagaries about relays and/or MikroTik's (lack of) SLA for the relays, make professional use more risky.