Skip to content
Topic

VPN

Any VPN: WireGuard, IPsec, L2TP, OpenVPN, SSTP, PPTP, EoIP: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per IP Cloud MikroTik: come funziona il nome DNS dinamico di RouterOS
Knowledge base
Knowledge base · IP Cloud

MikroTik IP Cloud: How RouterOS Dynamic DNS Works

IP Cloud is the free service that gives your router a fixed DNS name, serial-number.sn.mynetname.net, which follows the public IP address. The router asks the MikroTik server, "What address do you see me at?" and the name points to that answer, even behind a NAT. The name is used to find the router, not to open it.

7 min read
Illustrazione per VPN WireGuard dal telefono al MikroTik in 5 minuti, con il QR codeDojo

WireGuard VPN from your phone to MikroTik in 5 minutes, with QR code

Your phone joins your home or office network from any Wi-Fi, encrypted. With RouterOS 7, the router automatically generates the keys and phone configuration and displays a QR code to scan with the WireGuard app: interface, firewall, peer, split tunnel, and the precautions you need to know.

Illustrazione per IP Cloud MikroTik: un nome fisso per il router con l'IP dinamicoDojo

MikroTik IP Cloud: a fixed name for the router with a dynamic IP

IP Cloud is MikroTik's free dynamic DNS: it gives the router a fixed name that follows the public address even when it changes. How to enable it, how to verify it, what happens behind the ISP's modem, and why the name alone does not expose the router to the internet.

Illustrazione per CVE-2025-6443Security
CVE-2025-6443

VXLAN Vulnerability in RouterOS: CVE-2025-6443

CVE-2025-6443 is an improper access control vulnerability (CWE-284) in the VXLAN service of MikroTik RouterOS that allows a remote attacker, without authentication, to bypass access restrictions and reach internal network resources. Versions 7.15.3 and 7.16.2 are confirmed vulnerable by CVE.org, while NVD indicates all versions prior to 7.20; the exact fixed version has not yet been announced. Those using VXLAN on untrusted networks must update the firmware as soon as it becomes available and verify the service configuration.

Illustrazione per CVE-2025-42611Security
CVE-2025-42611

Certificate Validation Vulnerability in RouterOS

CVE-2025-42611 is a certificate validation vulnerability that may allow authentication bypass in services such as OpenVPN, CAPsMAN, and Dot1X. It affects RouterOS versions up to 7.20.x. The fixed version has not yet been announced; as of the article date, the vulnerability is not known to be actively exploited.

Medium · 6.5