● LIVE· № 001 · SANITIZE EVERYTHING THAT HITS GIT: CLEANING PUBLIC REPOS FROM IDENTITY LEAKS · 2026.05.11· № 002 · IMAGEGEN-MCP: A HOMEGROWN MCP SERVER FOR BLOG COVERS · 2026.05.11· № 003 · SMART PASTE: STRIPPING TERMINAL NOISE BEFORE PASTING, WITH ONE HOTKEY · 2026.05.10· № 004 · CLAUDE CODE TEAM TELEMETRY: CENTRALIZED USAGE STATS · 2026.05.07· № 005 · CLAUDE CODE ONBOARDING GUIDE FOR NEWCOMERS · 2026.05.06· 11 POSTS · 0 DRAFTS
EN / RU
·8 MIN

Back To Home VPN on MikroTik Chateau

MikroTik's free built-in remote-access service — managed WireGuard brokered through their cloud. The answer for routers behind double-NAT / CGNAT with no reachable public IP.

MikroTik's free built-in remote-access service — managed WireGuard brokered through their cloud. The answer for routers behind double-NAT / CGNAT with no reachable public IP.

What Back To Home is

Back To Home (BTH) is a free, managed WireGuard remote-access setup baked into RouterOS 7.12+. MikroTik's cloud service brokers the connection, so it works even when your router sits behind CGNAT (LTE) or inside another NAT with no port-forward.

Official apps (free):

  • iOS: MikroTik Back To Home on the App Store
  • Android: same app on Google Play
  • Windows / Linux / macOS: no native BTH app — import the generated WireGuard config into the standard WireGuard client

Enable BTH on the router

/ip cloud set ddns-enabled=yes
/ip cloud set back-to-home-vpn=enabled
/ip cloud print

Accepted values for back-to-home-vpn: enabled / revoked-and-disabled (there's no plain disabled once it's been enabled — revoking invalidates all issued peer keys).

CLI gotchas

A few things that bit me:

1. Menu path. It's a single /ip cloud menu with back-to-home-vpn as a property, plus a submenu /ip cloud back-to-home-user (singular). Things that look right but fail:

  • /ip cloud back-to-home set ... → bad command name
  • /ip cloud back-to-home-users ... (plural) → bad command name

2. Don't mix / and spaces in the command path. Either /ip cloud back-to-home-user print (all spaces) or /ip/cloud/back-to-home-user/print (all slashes). Mixing yields syntax error.

Add a peer per device

/ip cloud back-to-home-user add name=phone1 allow-lan=yes
/ip cloud back-to-home-user add name=android1 allow-lan=yes
/ip cloud back-to-home-user print

Expected output:

Flags: A - ACTIVE
#   NAME      EXPIRES  ALLOW-LAN  CLIENT-ADDRESS       FILE-ACCESS
0 A phone1    never    yes        192.168.216.3/32     disabled
1 A android1  never    yes        192.168.216.4/32     disabled

One user per device. If a phone is lost you can revoke just that peer without touching the others.

Options worth knowing:

  • allow-lan=yes — peer can reach 192.168.50.0/24 (otherwise only the router itself)
  • file-access=full|read-only|disabled — access to the router's /file over BTH
  • expires=<time> — auto-expiry, useful for temporary guest access

Get the client config / QR

Reliable way is WinBox — IP → Cloud → Back To Home Users → double-click the user → Show Client Config → scan the QR with the MikroTik Back To Home app.

CLI equivalent exists (/ip cloud back-to-home-user show-client-config) but the accepted argument format was finicky on 7.19.5 — WinBox is less fuss.

Does it work through LTE CGNAT?

Yes. Official docs and forum threads confirm BTH can relay the WireGuard handshake through MikroTik's cloud when the router has no reachable public IP. Tested live on this Chateau with LTE as the WAN — iPhone and Android both connect from mobile data.

Check where the cloud sees you:

/ip cloud print

If public-address is a private range (100.64.x, 10.x, 192.168.x) → you're on CGNAT and BTH is routing via the relay. Expect higher latency and a rate cap on throughput vs. a direct P2P tunnel — fine for SSH / RDP / file browsing, not great for 4K streaming.

Revoking a device

/ip cloud back-to-home-user disable [find name=android1]   # temporarily off
/ip cloud back-to-home-user remove [find name=android1]    # permanent revoke

If you need to nuke everything (all peer keys invalidated):

/ip cloud set back-to-home-vpn=revoked-and-disabled

Common problems

bad command name back-to-home

You used it as a submenu. It's a property of /ip cloud, not a menu:

/ip cloud set back-to-home-vpn=enabled

syntax error on user commands

Two usual causes:

  1. Mixed / and spaces in the path. Pick one style:
    /ip cloud back-to-home-user print
    # or
    /ip/cloud/back-to-home-user/print
  2. Menu is back-to-home-user (singular), not back-to-home-users.

show-client-config rejects the user argument

CLI argument format is finicky on 7.19.5. Use WinBox → IP → Cloud → Back To Home Users → double-click user → Show Client Config.

BTH peer connects but can't reach LAN

allow-lan was probably not set when the peer was added:

/ip cloud back-to-home-user set [find name=phone1] allow-lan=yes

Throughput feels slow (tens of Mbps)

That's the CGNAT relay doing its job — BTH bridges the handshake through MikroTik's infrastructure. Expect modest throughput. For heavy uploads/streaming you need a direct P2P path, which requires a public IP on at least one end.

Cheat sheet

# Enable
/ip cloud set ddns-enabled=yes
/ip cloud set back-to-home-vpn=enabled
/ip cloud print
 
# Add peers (one per device)
/ip cloud back-to-home-user add name=phone1 allow-lan=yes
/ip cloud back-to-home-user add name=android1 allow-lan=yes
/ip cloud back-to-home-user print
 
# Then in WinBox: IP → Cloud → Back To Home Users → Show Client Config → scan QR
 
# Manage peers
/ip cloud back-to-home-user disable [find name=android1]
/ip cloud back-to-home-user remove [find name=android1]
 
# Nuke all peers
/ip cloud set back-to-home-vpn=revoked-and-disabled

RouterOS: 7.19.5