// Engineering Log

Keenetic: Part 2 — VPN server for remote access

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

Why a VPN server on the router

When you need to reach a NAS, cameras, a work computer via RDP, or smart home devices from home or while traveling, opening their ports to the Internet is dangerous. It’s safer to run a VPN server directly on the router: a device connects to it over an encrypted tunnel and ends up inside the local network.

Keenetic supports several servers. Each is installed as a separate component and configured on the “Applications” page.

The main requirement — a public address

Almost all Keenetic VPN servers require a public IP address on the external interface; if KeenDNS is used, direct access mode is required. Without this, connecting to the server from the Internet will not work.

Exception — SSTP and OpenConnect. They work via KeenDNS cloud servers and allow connection even if both the client and the router have private addresses. The price for this is speed: it depends on cloud load.

Which servers are available

ServerSecurity levelSpeedBuilt-in client in OSIntended for
WireGuardvery highhighno, requires an appfor advanced users
IKEv2/IPsechighhighWindows, macOS, Linux, iOSfor regular users
L2TP/IPsechighhighWindows, macOS, Linux, Android, iOSfor regular users
SSTPhighmedium, lower via cloudWindowsfor regular users
OpenConnecthighmedium, lower via cloudno, requires an appfor regular users
OpenVPNvery highlowno, requires an appfor advanced users
PPTPlowmediumWindows, macOS, Linux, Androidonly for compatibility

Ratings are taken from Keenetic documentation. The number of simultaneous connections also depends on the protocol: IKEv2 and WireGuard are limited to 32 connections (on some models the limit for WireGuard has been raised), L2TP/IPsec has no limit, and PPTP, SSTP, and OpenConnect support 100 to 200 depending on the model.

What to choose

  • There is a public address, clients are employees’ laptops and phones: WireGuard. This is the simplest and fastest option, especially on mobile devices.
  • Cannot install third-party software: IKEv2 — the client is already built into Windows, macOS, iOS and Linux. L2TP/IPsec — as a fallback for older devices.
  • No public address: SSTP (built-in client in Windows) or OpenConnect — via the KeenDNS cloud.
  • Need compatibility with existing OpenVPN infrastructure: OpenVPN. The configuration is provided as a single file with embedded certificates and keys.
  • Do not use PPTP. The protocol is obsolete and its encryption is no longer considered secure.

GRE, IPIP and EoIP tunnels are not included in this list: these are not remote access but links between two routers. An example of such a tunnel — EoIP between MikroTik and Keenetic.

Example: WireGuard server

Starting with KeeneticOS 5.0, WireGuard got a separate app “WireGuard VPN Server” that creates clients and issues ready-made configuration files and QR codes.

  1. Install the WireGuard VPN Server component in the components settings.
  2. On the “Applications” page open WireGuard VPN Server.
  3. In the “Network access” field select the segment that will be available to clients, usually the home network.
  4. Set the server address in the tunnel from a private range that does not overlap with other router networks, for example 172.16.6.1/24. Clients will receive addresses from the same subnet.
  5. The “NAT for clients” option is enabled by default — it is needed if clients should access the Internet through the router.
  6. Click “Add client”, set a name, enable access and save. Download the configuration file or scan the QR code in the WireGuard app.

The client configuration file looks approximately like this:

ini
[Interface]
PrivateKey = <client private key>
Address = 172.16.6.2/32
DNS = 192.168.1.1

[Peer]
PublicKey = <router public key>
Endpoint = 203.0.113.10:51820
AllowedIPs = 192.168.1.0/24, 172.16.6.0/24
PersistentKeepalive = 25

In AllowedIPs the networks whose traffic will go through the tunnel are listed: here it’s the home network and the VPN subnet. To route all Internet traffic through the router, specify 0.0.0.0/0.

For more complex schemes, for example merging networks, WireGuard is configured as a regular connection on the “Other connections” page.

Server security

  • A separate account for each person. For servers with a login and password (SSTP, L2TP/IPsec, IKEv2, OpenConnect), disable simultaneous logins under the same name — this makes it easier to see who is connected and to revoke access.
  • Expose as little as possible. VPN clients should have access only to the selected segment, not the entire router network.
  • Updates. Keep KeeneticOS on the stable channel and update it: security fixes are delivered with regular releases.

Common mistakes

  • No public address. The ISP assigns a private address and the server is unreachable from the Internet. Check the address on the external interface or use SSTP and OpenConnect via the cloud.
  • Subnet overlap. If the client’s home network and the office network are both 192.168.1.0/24, routing breaks. For the office choose a less common range.
  • PPTP “because it’s easier”. Convenience does not justify poor security.
  • All traffic through the cloud. For SSTP via KeenDNS the manufacturer does not recommend NAT for clients: the throughput of a cloud connection is lower than direct.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply