Security and filtering
VPN connectivity
Connect people and sites securely over the Internet with VPN tunnels run by the router.
What it is
A virtual private network (VPN) carries traffic between your sites, or between remote staff and the office, across the Internet. RouterOS supports several VPN types, so you can pick the one your devices and clients support. A centralized design puts the main router at the core and connects each site or user to it.
Type: Wired and wireless. Works over either cabled or wireless links.
Link office sites
Join branch networks to the head office over the Internet.
Give staff remote access
Let staff and support teams reach internal systems from outside.
Manage client networks
Reach client equipment for support through a tunnel instead of opening it to the Internet.
Capabilities and hardware
What RouterOS provides for this solution, as described in MikroTik's documentation. Features depend on the RouterOS version, the hardware model and its licence level.
WireGuard
A simple, modern VPN with current cryptography that is cross-platform (Windows, macOS, BSD, iOS, Android) and widely deployable.
IPsec
A set of protocols for securing packet exchange over unprotected IP networks such as the Internet, including automatic key exchange (IKE).
Source: MikroTik documentation: IPsec
L2TP
A tunnelling protocol that can be used with or without encryption. L2TP itself does not encrypt the tunnelled traffic; running it over IPsec is the recommended secure approach.
Source: MikroTik documentation: L2TP
OpenVPN
Runs over UDP or TCP on a single port and can use a proxy. RouterOS has its own implementation, and not every OpenVPN feature is supported (for example LZO compression and cipher negotiation), so check compatibility with your clients.
Source: MikroTik documentation: OpenVPN
Choosing hardware
The VPN core needs a router that can handle your number of tunnels and the encryption load; remote sites can use smaller routers. Encryption speed differs between models, so size the core from the product's published figures rather than from the port speed.
Check before you buy. Features depend on the RouterOS version, the hardware model and its licence level, and not every MikroTik product supports every solution. Check the product page for the exact model before you buy.
Product recommendations for this solution are not listed yet: they are added once the product data is confirmed.
Help choosing
Who it helps
- Managed IT providersSecure access to client sites without exposing their internal systems to the Internet.
When it is a good fit
- You have more than one site that must share internal systems
- Staff or support engineers work away from the office
- You want one place to manage access to many sites
- Your clients' devices support a standard VPN type
- You can keep the VPN core available and monitored
Planning your setup
- Pick the VPN type. Choose from what your devices support: WireGuard, IPsec, L2TP (best used with IPsec) or OpenVPN. Each has different strengths and limits.
- Plan the core. A central router must handle the number of tunnels and the encryption load you expect, and be reachable.
- Plan addressing and routing. Give every site its own address range so sites can reach each other without overlap.
- Monitor and document. Record what each tunnel is for, and watch that each one stays up.
Related solutions
Not sure which one fits?
Tell us about your network and we will help you choose.
Talk to MikroTik CanadaSources
- MikroTik documentation: WireGuard (checked 2026-10-01)
- MikroTik documentation: IPsec (checked 2026-10-01)
- MikroTik documentation: L2TP (checked 2026-10-01)
- MikroTik documentation: OpenVPN (checked 2026-10-01)
- Existing MikroTik Canada page: Centralized VPN (checked 2026-10-01)
Capabilities are as described in the sources when they were checked. They depend on the RouterOS version, the hardware model and its licence level: confirm them for your model before you buy.