Free shipping on orders over $499* · Live warehouse stock · Competitive pricing · *See shipping details
Free shipping over $499* · *See details
Skip to content
MikroTik WireGuard VPN — road-warrior and site-to-site setup

MikroTik WireGuard VPN: Road-Warrior and Site-to-Site Setup (RouterOS v7)

WireGuard has quickly become the default VPN for people who want something fast, modern, and simple to audit. It is built into RouterOS v7, so any current MikroTik router can terminate tunnels with almost no CPU overhead. This guide walks through the two setups people ask for most: a road-warrior tunnel so a laptop or phone can reach the home or office network from anywhere, and a site-to-site tunnel that joins two networks together.

Every router linked below runs RouterOS v7 and is in stock at Javelin Networks with fast US shipping.

Why WireGuard on MikroTik

WireGuard uses modern cryptography, a tiny codebase, and a connectionless UDP design that reconnects instantly when a phone changes networks. On RouterOS it is a first-class interface type, which means you configure it with the same address, firewall, and routing tools you already use. Compared with the older IPsec and OpenVPN options, it is dramatically easier to get right and noticeably lighter on the router's CPU — which matters on small units like the hAP series.

What you need

You need one MikroTik router running RouterOS v7 at the site you want to reach, a public IP address (or a dynamic-DNS name) on its WAN, and the ability to forward one UDP port to it if it sits behind another router. On the client side you need the official WireGuard app (Windows, macOS, Linux, iOS, or Android). Any of these routers handle it comfortably:

  • hAP ax2 — the value pick for a home or small office terminating a handful of tunnels.
  • hAP ax3 — more CPU and a 2.5G port; a great all-round home/branch gateway. Browse the whole hAP family.
  • RB5009 — a faster edge router for an office with many remote users.
  • CCR2004 — for a central hub terminating dozens of site tunnels. See all routers & firewalls.

You will configure the router with WinBox or the terminal. The commands below are typed into the RouterOS terminal; each block is a few lines you can paste and edit.

Part 1: Road-warrior tunnel (laptop or phone to home)

The goal here is a single WireGuard interface on the router that remote devices dial into. Start by creating the interface and giving it an address on a new, dedicated subnet (we use 10.10.10.0/24):

/interface/wireguard add name=wg-rw listen-port=13231
/ip/address add address=10.10.10.1/24 interface=wg-rw

Print the interface to copy the router's public key — you will paste it into each client:

/interface/wireguard print

Now add a peer for each client. Each device has its own key pair and its own address inside the tunnel subnet. Generate the client key in the WireGuard app, then paste its public key here:

/interface/wireguard/peers add interface=wg-rw \
    public-key="CLIENT_PUBLIC_KEY" allowed-address=10.10.10.2/32

Open the listen port on the router's firewall so clients can reach it, and allow the tunnel traffic into your LAN:

/ip/firewall/filter add chain=input protocol=udp dst-port=13231 action=accept \
    comment="WireGuard"
/ip/firewall/filter add chain=forward in-interface=wg-rw action=accept \
    comment="Allow WG to LAN"

Finally, build the client configuration in the WireGuard app. For a full tunnel (all traffic goes through home), set AllowedIPs = 0.0.0.0/0. For a split tunnel (only reach the home LAN), set AllowedIPs to your LAN subnet, e.g. 192.168.88.0/24:

[Interface]
PrivateKey = CLIENT_PRIVATE_KEY
Address = 10.10.10.2/32

[Peer]
PublicKey = ROUTER_PUBLIC_KEY
Endpoint = your-public-ip-or-ddns:13231
AllowedIPs = 0.0.0.0/0
PersistentKeepalive = 25

If you chose a full tunnel, make sure your router already masquerades its WAN (/ip/firewall/nat with action=masquerade on the WAN out-interface) so the client's traffic gets out to the internet.

Part 2: Site-to-site tunnel (office A to office B)

A site-to-site link is the same idea, but each router is a peer of the other and each advertises its own LAN. On Router A (LAN 192.168.10.0/24):

/interface/wireguard add name=wg-s2s listen-port=13231
/ip/address add address=10.20.20.1/30 interface=wg-s2s
/interface/wireguard/peers add interface=wg-s2s \
    public-key="ROUTER_B_PUBLIC_KEY" endpoint-address=B_PUBLIC_IP \
    endpoint-port=13231 allowed-address=10.20.20.2/32,192.168.20.0/24 \
    persistent-keepalive=25s
/ip/route add dst-address=192.168.20.0/24 gateway=wg-s2s

On Router B (LAN 192.168.20.0/24) you mirror it — swap the subnets and point the peer back at Router A. The key detail is allowed-address: it must list the remote tunnel IP and every remote LAN subnet you want to reach, and you add a matching route so RouterOS knows to send that traffic over the tunnel. Then allow the forwarded traffic on both firewalls:

/ip/firewall/filter add chain=forward in-interface=wg-s2s action=accept
/ip/firewall/filter add chain=forward out-interface=wg-s2s action=accept

Firewall and routing notes that save you a support call

  • Behind another router? Forward UDP 13231 to your MikroTik, or the handshake never completes.
  • No public IP? Use a dynamic-DNS name in the client Endpoint. RouterOS has a built-in cloud DDNS under /ip/cloud.
  • Handshake works but no traffic? It is almost always AllowedIPs (client) or allowed-address (router) missing the subnet you are trying to reach, or a missing route.
  • Keep mobile tunnels alive with PersistentKeepalive = 25 so NAT mappings on cellular networks do not time out.

Which router should you run it on?

hAP ax2

Best for: A home or small office with a few remote users

Role Home/branch gatewayTunnels A handfulWi-Fi Wi-Fi 6 built in
hAP ax3

Best for: A busier home/branch wanting 2.5G and more headroom

Role Home/branch gatewayPort 2.5 GbpsWi-Fi Wi-Fi 6 built in
RB5009

Best for: An office terminating many remote workers

Role Edge routerPorts 7×1G + 2.5G + SFP+Wi-Fi None (wired)
CCR2004

Best for: A central hub joining dozens of sites

Role Hub/core routerUplinks 2×SFP+Scale Dozens of tunnels

Not sure which fits? Browse the full MikroTik range or reach out and we will help you spec it.

Frequently asked questions

Does every MikroTik router support WireGuard?

Any router running RouterOS v7 does — WireGuard was added as a built-in interface type in v7. If you are still on RouterOS v6, upgrade to v7 first. All current MikroTik models ship with v7.

Is WireGuard faster than IPsec or OpenVPN on MikroTik?

For most small routers, yes. WireGuard's lightweight design means lower CPU use and higher throughput than OpenVPN, and it is far simpler to configure than IPsec. On big routers with hardware IPsec acceleration, raw IPsec throughput can still be higher, but WireGuard wins on simplicity.

Can I use WireGuard without a public IP address?

Yes, as long as one end can be reached. Use a dynamic-DNS name (RouterOS has built-in cloud DDNS) and forward the UDP port if your router sits behind another one. If both ends are behind carrier-grade NAT, you will need a cloud relay instead.

How many devices can connect at once?

Each client is just another peer, so the practical limit is the router's CPU rather than a licensed user count. A hAP handles a household or small team; an RB5009 or CCR handles dozens to hundreds.

What port should I use?

Any free UDP port works; 13231 is MikroTik's default and 51820 is the WireGuard default. Pick one, open it in the firewall, and use the same number in every client's Endpoint.

Ready to build your tunnel? Pick a router from the MikroTik collection and you will be up in an afternoon.

Previous article Point-to-Point Wireless Backhaul: airFiber vs MikroTik vs Cambium vs Siklu
Next article Your First MikroTik Router: First-Time Setup and Securing RouterOS (2026)