Secure Remote Access

Your MikroTik.
From anywhere.

An encrypted tunnel that reaches routers, CCTV systems and servers sitting behind CGNAT — with a static VPN address that never changes. No public IP. No port forwarding. No firewall archaeology.

Uptime SLA
99.9%
Devices online
2,400+
Support
24/7
MikroTik RB5009
behind CGNAT
PingSphere Core
AES-256 · MNL-01
Winbox / SSH
10.200.1.42
MikroTik Winbox
SSH Access
WebFig
RouterOS API
SNMP Monitoring
CCTV · DVR · NVR
NAS & Servers
Internal LAN Resources
01 / Capabilities

Everything the tunnel does, so you don't have to.

Enterprise-grade connectivity, stripped of the parts that usually make it a two-day job.

/01

Encrypted MikroTik access

An AES-256 tunnel from your router to the PingSphere core. Every Winbox session, every SSH keystroke, every SNMP poll travels inside it — and nothing about your network is exposed to the open internet.

/02

Zero port forwarding

Your router dials out. Nothing dials in. That single inversion removes the NAT rules, the firewall exceptions, and the standing invitation to every scanner on the internet.

0 inbound ports open
/03

Works behind CGNAT

Dynamic IPs, shared carrier NAT, LTE and Starlink links — all fine. The tunnel doesn't care what's upstream.

/04

A static VPN address

Each device keeps a permanent 10.200.x.x address. Bookmark it once; it still works next year.

/05

Many devices, one account

Routers, switches, NVRs and servers across every site, addressed from a single console.

/06

Six lines of RouterOS

One ovpn-client block and you're up. No advanced networking required.

/07

Support that speaks RouterOS

A Philippines-based team on call around the clock — engineers who have configured the same hardware you're holding, not a script-reading first line.

02 / Setup

Six lines. One reboot you won't need.

Paste the client block into RouterOS. The router opens the tunnel outbound and your static address is waiting on the other side.

01

Router dials out. An outbound TLS connection to the nearest PingSphere core.

02

Address is issued. The same 10.200.x.x address every time the link comes up.

03

You connect. Winbox, SSH, WebFig, API or your NMS — pointed at the VPN address.

RouterOS 7.x — terminal
# attach this router to PingSphere
[admin@MikroTik] > /interface ovpn-client add \
... connect-to=core.pingsphere.net \
... user=ps-4417 password=•••••••••• \
... certificate=pingsphere.crt \
... add-default-route=no disabled=no
 
# confirm the address came up
[admin@MikroTik] > /ip address print where interface=ovpn-out1
# ADDRESS NETWORK INTERFACE
0 10.200.1.42/24 10.200.1.0 ovpn-out1
 
# tunnel is up — reachable from anywhere
[admin@MikroTik] >
03 / Solutions

Five ways people stop driving to site.

One tunnel, shaped to whatever it is you actually have to reach.

04 / How it works

Four steps, roughly ten minutes.

01

Subscribe

Pick a plan and your account is provisioned immediately.

02

Connect the router

Paste the RouterOS client block. The tunnel comes up outbound.

03

Take your address

A static VPN IP is bound to that device, permanently.

04

Reach it anywhere

Winbox, SSH, WebFig, API or your own monitoring stack.

05 / Console

Every device, one page.

Live reachability, assigned addresses and round-trip times across the whole fleet.

pingsphere.net/console — fleet overview
4 of 5 reachable

Connected devices

synced 2s ago
DeviceVPN addressSiteRTTState
hAP ac²10.200.1.15Makati Online
CCR103610.200.1.23Cebu DC Online
RB500910.200.1.42Davao Online
Chateau LTE10.200.1.57Site B Offline
CRS32610.200.1.88BGC Online
06 / Why PingSphere

Built by network engineers, for network engineers.

We have run these networks. The product is shaped by the parts that hurt.

AES-256 end to end

Every byte between your device and the core is encrypted. Nothing traverses the public internet in the clear.

Latency you can work in

Regional cores and optimised routing keep Winbox responsive instead of laggy and unusable.

Addresses that persist

A permanent VPN IP per device. Scripts, bookmarks and NMS entries keep working indefinitely.

Native to RouterOS

No agents, no custom firmware, no vendor lock-in. Standard RouterOS features, configured properly.

CGNAT is a non-issue

Because the connection is outbound, carrier NAT, dynamic IPs and LTE links stop being obstacles.

99.9% uptime SLA

Redundant cores with automatic failover, so the tunnel is up when the call comes in at 2am.

07 / Pricing

Priced per router, not per headache.

No setup fees, no contracts, no surprise overage. Cancel whenever you like.

Starter

Home labs & single sites
199/mo

One router, one static address — everything you need to reach the house from the office.

  • 1 MikroTik router
  • Static VPN address
  • AES-256 encrypted tunnel
  • Email support
Choose Starter
Most chosen

Professional

Save 17%
Technicians & multi-site
499/mo

Built for the person carrying five client networks in their head at once.

  • Up to 5 MikroTik routers
  • Static address per device
  • AES-256 encrypted tunnel
  • CCTV & NVR support
  • Priority support
Choose Professional
Most popular with field technicians

Business

Save 33%
ISPs & organisations
999/mo

For fleets — subscriber bases, branch estates and anything measured in hundreds.

  • Unlimited routers
  • Static address per device
  • AES-256 encrypted tunnel
  • Console API access
  • Dedicated account manager
  • Full service support
Choose Business
08 / Questions

The things people ask first.

Yes. Once the router holds the tunnel open, its VPN address is reachable from any internet connection in the world — Winbox, SSH, WebFig, the RouterOS API, or whatever monitoring tool you already run.

No. The router makes an outbound connection to us, which means it works on a plain residential or LTE line with no public IP, no dynamic DNS and no port forwarding.

It does. Carrier-grade NAT only blocks inbound connections, and PingSphere never needs one. This is the single most common reason people sign up.

One on Starter, five on Professional, and unlimited on Business. Every device gets its own static address and appears in the same console.

All traffic inside the tunnel is protected with AES-256-GCM. Certificates are issued per device, so a compromised credential can be revoked on its own without touching the rest of your fleet.

RouterOS re-dials automatically and the same static address is reissued, so nothing downstream has to be reconfigured. Cores are redundant with automatic failover behind a 99.9% uptime SLA.

Stop driving to site.

Bring your MikroTik routers, CCTV systems and servers onto one encrypted, permanently addressable network — without a public IP, and without touching a single firewall rule.

No setup fee · No contract · Cancel anytime
Chat with us