In short: IP Cloud is the free service that allows RouterOS to assign a fixed DNS name, numero-di-serie.sn.mynetname.net, to the router, which follows the public IP address. The router asks the MikroTik server “what address do you see me at?” and the name points to that response, even behind a NAT. The name is used to find the router, not to open it.

What is IP Cloud?

It is the /ip cloud menu, which collects MikroTik’s free cloud services: dynamic DNS (DDNS), time on boot, and Back To Home. This page explains how DDNS works internally. For a step-by-step guide on how to enable it, see the howto IP Cloud MikroTik: a fixed name for the router with a dynamic IP.

The router always initiates the connection to the MikroTik servers. Therefore, DDNS does not require any port forwarding on the modem in front of it.

It works on RouterBOARDs and CHR with a paid perpetual license. It is not available on RouterOS installed on an x86 PC.

How does the router discover its public address?

It asks the MikroTik server. The router sends an encrypted request to cloud2.mikrotik.com and the server responds with the address from which it received the request. That address ends up in public-address.

/ip cloud print
          ddns-enabled: yes
  ddns-update-interval: none
           update-time: yes
        public-address: 203.0.113.10
              dns-name: hf1234abcd5.sn.mynetname.net
                status: updated
      back-to-home-vpn: revoked-and-disabled

The router does not look at the addresses of its interfaces: it looks at how it is seen from the internet. This leads to three points:

  • behind a NAT, public-address is the address of the modem or the router performing NAT, not an address of the MikroTik device;
  • with multiple internet lines, according to the documentation, it is the address of the line using the route to cloud2.mikrotik.com: with a failover, the name follows the line carrying that route;
  • with IPv6: according to the documentation, if the router reaches the server via IPv6 as well, public-address-ipv6 appears and the name also resolves to that address.

public-address appears after the first server response, even when only the time update is running and DDNS is disabled.

What does the name look like?

It is the router’s serial number in lowercase, followed by .sn.mynetname.net. You do not choose it and it does not change: it remains tied to that specific device. It resolves to public-address with a TTL of 60 seconds.

Do you need your own name? Create a CNAME record in your domain pointing to the sn.mynetname.net name.

⚠️ Warning: the serial number is on the label and the box. Anyone who knows it can find your public address. The name is not a secret: protection is provided by the input firewall, as in Basic Hardening of a MikroTik Router.

When does the router update the name?

Automatically, when needed. Behind a NAT, where the router does not see the public address on its interfaces, it sends an update every minute. If you want more frequent updates at a fixed interval, there is ddns-update-interval: the default is none, the minimum is 1 minute.

/ip cloud set ddns-update-interval=10m
/ip cloud force-update

force-update sends an update immediately, for example after you have changed the line. With DDNS disabled, it does nothing.

You can read the status of the last request in status:

  • updated: the server has confirmed;
  • updating...: the router has sent the request and is waiting for the response. If it does not arrive, it retries at increasingly longer intervals.

What does ddns-enabled=auto mean?

It means that DDNS is enabled only while Back To Home is enabled. auto is the factory default; with yes DDNS remains always enabled.

When you disable DDNS, the router asks the server to remove the name: in the lab, it stopped resolving in less than a minute. If you are using Back To Home, simply re-enabling auto is not enough: DDNS remains enabled until you also disable Back To Home.

What happens behind a NAT or a CGNAT?

The name points to the right place, but the port may be closed. Behind the ISP’s modem, the name resolves to the modem’s public IP address, and /ip cloud print shows the warning Router is behind a NAT. Remote connection might not work.

With your own NAT, you forward the required port on the modem to the MikroTik, for example the VPN UDP port. With the ISP’s CGNAT, the public IP address belongs to the ISP’s NAT and you cannot forward the port yourself: the name resolves, but you cannot get in from outside. In that case, you need Back To Home, which goes through a MikroTik relay.

There is also the opposite case: you want the name to resolve to the router’s local IP address inside the network.

/ip cloud advanced set use-local-address=yes

With yes, the name points to the address from which the router sends requests, for example a private address like 10.6.0.2/12 behind the lab NAT (adjust the addresses to your network). public-address continues to show the public IP address. Warning: from outside, that name no longer leads to the router.

In the lab, the name switched to the private IP address after just over a minute. When you re-enable use-local-address=no, also run /ip cloud force-update: without it, the name remained on the private IP address.

What is Back To Home?

It is a pre-configured WireGuard VPN that you set up from the Back To Home app on your phone and that works even without a public IP address. When the router is not directly reachable, the phone goes through a MikroTik relay; encryption remains end-to-end and the relay does not read the traffic.

It uses its own name, numero-di-serie.vpn.mynetname.net, and with ddns-enabled=auto it also enables DDNS. For a VPN under your control, the way to go is still manually configured WireGuard.

What does the router send to the MikroTik servers?

Only what is needed for the services you have enabled. By default, the router asks the server, at startup, for the time and the time zone (update-time and time-zone-autodetect); DDNS does not. For the time zone, the server looks up the location of your public IP address.

If you do not want any requests to cloud2.mikrotik.com:

/ip cloud set ddns-enabled=auto back-to-home-vpn=revoked-and-disabled update-time=no
/system clock set time-zone-autodetect=no

The time from the cloud is approximate: if the NTP client is enabled, the router does not use it anyway. Detect Internet is a different thing: it talks to cloud.mikrotik.com on UDP port 30000 and is disabled by default.

What are the typical errors?

The name resolves, but I cannot get in from outside

The name is used to find the router, it does not open ports. Check in this order: the MikroTik input firewall, the port forwarding on the modem in front, and whether you are behind a CGNAT. In the third case, no forwarding will save you.

status remains on updating…

The router does not receive a response from cloud2.mikrotik.com. Check that the router resolves DNS names and that no output rule, or an upstream firewall, blocks the router’s traffic to the internet. On a CHR, verify that you have a paid perpetual license.

The IP address changed but the name did not

Behind a NAT, the router updates every minute and the TTL is 60 seconds: wait a couple of minutes, or run /ip cloud force-update. If the PC still responds with the old IP address, try with another resolver: it may be the client’s DNS cache.

I set auto but the name still resolves

Two possibilities: Back To Home is enabled, in which case DDNS remains active; or you are checking within the first few minutes, before the deletion takes effect.

Where do I use it?

All properties are documented in the MikroTik manual: Cloud.

Tested in the lab on a routerboard running RouterOS 7.24.5 (stable), behind NAT: public-address and NAT warning, name matching the serial number with TTL 60, minimum limit of 1 minute for ddns-update-interval, force-update, use-local-address (name on the private address and return with force-update), name deletion with ddns-enabled=auto. Multiple lines, IPv6, and CHR licenses are covered in the documentation.

Frequently asked questions

How does the MikroTik know its public IP if it is behind the modem?

It asks the MikroTik server: it sends a request to cloud2.mikrotik.com and the server responds with the address from which it received the request. Behind a NAT, this is the public address of the modem.

How often is the IP Cloud name updated?

Behind a NAT, the router sends an update every minute, and the name has a TTL of 60 seconds. You can add periodic updates with ddns-update-interval (minimum 1 minute) or force one with /ip cloud force-update.

Does IP Cloud work with CGNAT?

The name does: it resolves to the public address of the operator’s NAT. However, you cannot reach the router from outside, because you cannot port forward on that NAT. In that case, you need Back To Home, which goes through a MikroTik relay.

Does IP Cloud work on CHR?

Yes, but only with a paid perpetual license. It is not available on RouterOS for x86.

How do I turn off IP Cloud?

With /ip cloud set ddns-enabled=auto, with Back To Home disabled. The router asks the server to delete the name, which stops resolving within a few minutes.