Secure insecure webservices with microtik

Hi!

We have some devices that we need to publish for several technicians outside a costumers network. They are insecure so we need to make something more than just port forwarding. The technicians don’t come from a static address so I can’t filter based on source address.

Any ideas on how to solve this with just a mikrotik-router?

  • Port knocking would be doable if we script the port knock process on the client machines. But not very convenient
  • VPN would also be doable, but not optimal due to some circumstances

Why not use both?

I am using only VPN is such situation and its very useful, especially pptp vpn, i can connect to my network using any Windows or Linux machine, also with my Android too :slight_smile: