Community discussions

MikroTik App
 
User avatar
atomicduck
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Fri Oct 02, 2020 1:42 pm

How to reach a router behind a CGNAT?

Sat Dec 21, 2024 11:06 am

I have a user that will use a residential StarLink on location, and that thing is behind a CGNAT.

How to punch through to make a WireGuard work for remote access / admin?
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12979
Joined: Thu Mar 03, 2016 10:23 pm

Re: How to reach a router behind a CGNAT?  [SOLVED]

Sat Dec 21, 2024 11:16 am

BTH function is done exactly for such cases.
 
User avatar
atomicduck
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Fri Oct 02, 2020 1:42 pm

Re: How to reach a router behind a CGNAT?

Sat Dec 21, 2024 12:24 pm

Thank you very much! 8)
 
User avatar
patrikg
Member
Member
Posts: 362
Joined: Thu Feb 07, 2013 6:38 pm
Location: Stockholm, Sweden

Re: How to reach a router behind a CGNAT?

Sat Dec 21, 2024 2:02 pm

But don't do it in prod.

It's only for HO.
 
User avatar
atomicduck
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Fri Oct 02, 2020 1:42 pm

Re: How to reach a router behind a CGNAT?

Sat Dec 21, 2024 9:22 pm

But don't do it in prod.

It's only for HO.
Why? It is WireGuard, with specific client in. Should be quite safe. Or? What am I missing?

(I have done some tests today, but nothing much. Didn't work out of the box, need some tweaking.)
 
User avatar
patrikg
Member
Member
Posts: 362
Joined: Thu Feb 07, 2013 6:38 pm
Location: Stockholm, Sweden

Re: How to reach a router behind a CGNAT?

Sat Dec 21, 2024 10:08 pm

It's working today, but maybe not tomorrow.
Take a look at this answer from Mikrotik Own Support Technician.
viewtopic.php?p=1114268#p1114268
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21893
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: How to reach a router behind a CGNAT?

Sun Dec 22, 2024 1:37 am

A bit over the top, but it should not be used as a business entity as on occasion, not very frequently the Mikrotik servers have gone offline. A couple of times a year is probably a safe bet.
Nothing for you to worry about unless your a hospital, a bank or any business requiring 24/7 VPN up time.
If that is concern then rent a server in the cloud, for like $7 a month and put a CHR on it and use that as the wireguard server.
 
User avatar
atomicduck
Member Candidate
Member Candidate
Topic Author
Posts: 265
Joined: Fri Oct 02, 2020 1:42 pm

Re: How to reach a router behind a CGNAT?

Sun Dec 22, 2024 1:38 pm

A bit over the top, but it should not be used as a business entity as on occasion, not very frequently the Mikrotik servers have gone offline. A couple of times a year is probably a safe bet.
Exactly my point. If a client is not willing to shelve out for a business connection with an fixed IP, then I don't really see them willing to finance a CHR instance configuration and maintenance.
Nothing for you to worry about unless your a hospital, a bank or any business requiring 24/7 VPN up time.
If that is concern then rent a server in the cloud, for like $7 a month and put a CHR on it and use that as the wireguard server.
As on the price of the cloud server - the issue is not a few bucks needed to make it work, but time to do so. All these costs need to be passed onto the client, and it adds up. It is simply more cost effective to have a business class internet access.

Also, 24/7 is overrated for most use cases.

(Also, I haven't forgot about that EAP I promised you, but I have so much work to do that I couldn't yet muster time to do a write up.)
 
optio
Forum Veteran
Forum Veteran
Posts: 945
Joined: Mon Dec 26, 2022 2:57 pm

Re: How to reach a router behind a CGNAT?

Sun Dec 22, 2024 2:09 pm

Why is CHR necessary just for Wireguard peer? It can be setup on Linux running on cloud server and save some money for CHR licence. Once setup on Linux is created, image can be made of it for reuse.
Initially some time will be spent to create setup, but later it should be more faster and charge more know-how than spent time and profit from such clients.
 
User avatar
sindy
Forum Guru
Forum Guru
Posts: 11115
Joined: Mon Dec 04, 2017 9:19 pm

Re: How to reach a router behind a CGNAT?

Sun Dec 22, 2024 2:22 pm

So we must clarify what business use means. If the BTH is used for occasional management access for a support company, then support intervention is not possible if the BTH infrastructure is unavailable. That's definitely unpleasant but it is not the same like if BTH was hypothetically used to provide service for end customers, because support interventions are only required at random times and the BTH infrastructure becomes unavailable at other random times, so the probability that these two events coincide is not that high.

But looking at it from the other side, if I provide support, it should not be a big deal for me to have a public (or global) IP address and let these customers actively connect to it so that I could reach their router for support interventions?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 21893
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: How to reach a router behind a CGNAT?

Sun Dec 22, 2024 2:47 pm

Concur with Sindy, if you are providing a paid service, then having your own cloud wireguard to support all your clients ( shared cost ), is the smart way to go.

Who is online

Users browsing this forum: CGGXANNX, ciruliss, parm and 34 guests