MikroTik's free built-in remote-access service — managed WireGuard brokered through their cloud. The answer for routers behind double-NAT / CGNAT with no reachable public IP.
What Back To Home is
Back To Home (BTH) is a free, managed WireGuard remote-access setup baked into RouterOS 7.12+. MikroTik's cloud service brokers the connection, so it works even when your router sits behind CGNAT (LTE) or inside another NAT with no port-forward.
Official apps (free):
- iOS: MikroTik Back To Home on the App Store
- Android: same app on Google Play
- Windows / Linux / macOS: no native BTH app — import the generated WireGuard config into the standard WireGuard client
Enable BTH on the router
/ip cloud set ddns-enabled=yes
/ip cloud set back-to-home-vpn=enabled
/ip cloud printAccepted values for back-to-home-vpn: enabled / revoked-and-disabled (there's no plain disabled once it's been enabled — revoking invalidates all issued peer keys).
CLI gotchas
A few things that bit me:
1. Menu path. It's a single /ip cloud menu with back-to-home-vpn as a property, plus a submenu /ip cloud back-to-home-user (singular). Things that look right but fail:
/ip cloud back-to-home set ...→bad command name/ip cloud back-to-home-users ...(plural) →bad command name
2. Don't mix / and spaces in the command path. Either /ip cloud back-to-home-user print (all spaces) or /ip/cloud/back-to-home-user/print (all slashes). Mixing yields syntax error.
Add a peer per device
/ip cloud back-to-home-user add name=phone1 allow-lan=yes
/ip cloud back-to-home-user add name=android1 allow-lan=yes
/ip cloud back-to-home-user printExpected output:
Flags: A - ACTIVE
# NAME EXPIRES ALLOW-LAN CLIENT-ADDRESS FILE-ACCESS
0 A phone1 never yes 192.168.216.3/32 disabled
1 A android1 never yes 192.168.216.4/32 disabledOne user per device. If a phone is lost you can revoke just that peer without touching the others.
Options worth knowing:
allow-lan=yes— peer can reach192.168.50.0/24(otherwise only the router itself)file-access=full|read-only|disabled— access to the router's/fileover BTHexpires=<time>— auto-expiry, useful for temporary guest access
Get the client config / QR
Reliable way is WinBox — IP → Cloud → Back To Home Users → double-click the user → Show Client Config → scan the QR with the MikroTik Back To Home app.
CLI equivalent exists (/ip cloud back-to-home-user show-client-config) but the accepted argument format was finicky on 7.19.5 — WinBox is less fuss.
Does it work through LTE CGNAT?
Yes. Official docs and forum threads confirm BTH can relay the WireGuard handshake through MikroTik's cloud when the router has no reachable public IP. Tested live on this Chateau with LTE as the WAN — iPhone and Android both connect from mobile data.
Check where the cloud sees you:
/ip cloud printIf public-address is a private range (100.64.x, 10.x, 192.168.x) → you're on CGNAT and BTH is routing via the relay. Expect higher latency and a rate cap on throughput vs. a direct P2P tunnel — fine for SSH / RDP / file browsing, not great for 4K streaming.
Revoking a device
/ip cloud back-to-home-user disable [find name=android1] # temporarily off
/ip cloud back-to-home-user remove [find name=android1] # permanent revokeIf you need to nuke everything (all peer keys invalidated):
/ip cloud set back-to-home-vpn=revoked-and-disabledCommon problems
bad command name back-to-home
You used it as a submenu. It's a property of /ip cloud, not a menu:
/ip cloud set back-to-home-vpn=enabledsyntax error on user commands
Two usual causes:
- Mixed
/and spaces in the path. Pick one style:/ip cloud back-to-home-user print # or /ip/cloud/back-to-home-user/print - Menu is
back-to-home-user(singular), notback-to-home-users.
show-client-config rejects the user argument
CLI argument format is finicky on 7.19.5. Use WinBox → IP → Cloud → Back To Home Users → double-click user → Show Client Config.
BTH peer connects but can't reach LAN
allow-lan was probably not set when the peer was added:
/ip cloud back-to-home-user set [find name=phone1] allow-lan=yesThroughput feels slow (tens of Mbps)
That's the CGNAT relay doing its job — BTH bridges the handshake through MikroTik's infrastructure. Expect modest throughput. For heavy uploads/streaming you need a direct P2P path, which requires a public IP on at least one end.
Cheat sheet
# Enable
/ip cloud set ddns-enabled=yes
/ip cloud set back-to-home-vpn=enabled
/ip cloud print
# Add peers (one per device)
/ip cloud back-to-home-user add name=phone1 allow-lan=yes
/ip cloud back-to-home-user add name=android1 allow-lan=yes
/ip cloud back-to-home-user print
# Then in WinBox: IP → Cloud → Back To Home Users → Show Client Config → scan QR
# Manage peers
/ip cloud back-to-home-user disable [find name=android1]
/ip cloud back-to-home-user remove [find name=android1]
# Nuke all peers
/ip cloud set back-to-home-vpn=revoked-and-disabledLinks
RouterOS: 7.19.5
