No Public IP? No Problem!

Manage MikroTik Hotspots Without Public IP

The world's easiest solution for ISPs and Hotels behind CGNAT or Dynamic IPs. Deploy secure, cloud-managed hotspots in seconds using our WireGuard-powered technology.

30-Second Setup Encrypted VPN No Port Forwarding
YesSpot Dashboard - No Public IP Management

Connection Status

Connected (VPN)

Why Traditional Solutions Fail

Most cloud hotspot managers require a Static Public IP address. This creates major headaches for modern ISPs and businesses.

High Cost of Static IPs

Static Public IPs are expensive and becoming harder to get from ISPs. Paying ongoing monthly fees just for management eats into your profits.

CGNAT Blocks Access

Many ISPs use CGNAT (Carrier-Grade NAT), which shares one public IP among many users. Standard port forwarding is impossible in this environment.

Security Risks

Opening ports on your router to the public internet invites hackers and botnets. It's a massive security vulnerability for your network.

The Solution

How YesSpot Works Without Public IP

We've integrated WireGuard® VPN technology directly into our platform to create a secure, invisible tunnel between your router and our cloud.

1

Copy Script

Create a hotspot in your YesSpot dashboard and copy the auto-generated setup script.

2

Paste in Terminal

Paste the script into your MikroTik Terminal. No manual configuration tailored for your specific router is needed.

3

Intelligent Tunnel

The script creates a secure WireGuard tunnel that punches through CGNAT and connects instantly.

Ready to ditch your Public IP expenses?

Join hundreds of ISPs and hotel managers who have switched to YesSpot's effortless cloud management.

Under the Hood

Powered by WireGuard®

We replaced legacy VPN protocols with WireGuard. It's a modern, high-performance VPN that is purpose-built for speed and security.

  • Extremely Lightweight

    Minimal CPU usage on your MikroTik router compared to OpenVPN or IPsec.

  • Roaming Capable

    Handles dynamic IP changes instantly. If your ISP changes your WAN IP, the tunnel reconnects in milliseconds.

  • Cryptographically Secure

    Uses state-of-the-art cryptography (Noise protocol framework, Curve25519, ChaCha20, Poly1305).

MikroTik Terminal

[admin@MikroTik] > /interface/wireguard/print

Flags: X - disabled, R - running

0 R name="yesspot-tunnel" mtu=1420 listen-port=13231

private-key="*******" public-key="*******"

[admin@MikroTik] > /ping 10.10.10.1 count=3

SEQ HOST SIZE TTL TIME STATUS

0 10.10.10.1 56 64 24ms

1 10.10.10.1 56 64 23ms

2 10.10.10.1 56 64 24ms

sent=3 received=3 packet-loss=0% min-rtt=23ms avg-rtt=23ms max-rtt=24ms

_

Frequently Asked Questions

Do I really not need a public IP?
Correct. Unlike traditional RADIUS servers that need incoming connections (CoA), YesSpot establishes an outgoing permanent tunnel from your router to our cloud. This bypasses the need for any incoming public IP on your side.
Does it work with 4G/5G routers?
Yes! Mobile networks are notorious for using CGNAT, which makes remote management impossible with other software. YesSpot works perfectly over 4G/LTE/5G connections.
Is there an extra cost for this feature?
No. The "No Public IP" functionality is included in all our plans, starting from the Free Trial. We don't charge extra for the VPN tunnel technology.
What MikroTik models are supported?
We support all MikroTik routers running RouterOS v7.x (which has native WireGuard support). For older RouterOS v6.x, we have alternative connection methods, but we highly recommend upgrading to v7.