Permanent access addresses

Give every router a permanent address — even without a public IP.

MUA VPN connects your MikroTik router — or a Windows or Linux machine — to our server over an outbound WireGuard tunnel. You get one fixed address you can reach with Winbox, SSH, WebFig or RDP, whether the line sits behind CGNAT, Starlink, or a shared ISP connection. No port forwarding. No calls to your ISP.

7-day free trial, no credit card Billed per router, monthly, via M-Pesa RouterOS v7+, Windows and Linux
A router behind CGNAT has no reachable address A MikroTik router sits behind an ISP network that shares one public address among many customers. Incoming connections from the internet cannot reach the router. Your router 192.168.88.1 Carrier NAT / CGNAT one public IP, many users no inbound mapping You, remote no way in Inbound connections stop here. Port forwarding on your router does not help. Starlink, fixed wireless and many fibre plans behave the same way.

The problem: an outbound-only connection is unreachable from the outside.

The problem

You cannot reach a router that has no address to reach.

If the line does not have a static public IP, or the operator puts you behind carrier-grade NAT, the router is effectively invisible from the internet. Everything works outbound — customers browse, devices connect — but nothing can dial in.

  • No public IP. The router holds a private address that only exists inside the ISP network.
  • CGNAT. Hundreds of customers share one public address, so there is no port to forward to you.
  • Starlink and fixed wireless. The public address you see today can change without warning.
  • No port forwarding. Without a public address on the outside, there is nothing to forward.
  • The ISP will not help. A public IP is often an upsell, unavailable, or not offered on your plan at all.

MUA VPN works with the connection you already have. The router dials out to us and keeps the tunnel open, so we always know where it is — and so do you.

How it works

Three steps from an unreachable router to a permanent address.

No new hardware, no static IP order, no waiting on the ISP.

  1. 1

    We generate a script for your router

    Tell us the router's identity and we prepare a small RouterOS script file (.rsc) that contains its WireGuard key, the tunnel endpoint, and the access address reserved for it. Nothing on your network is changed until you run it.

  2. 2

    You import it in one command

    Open a terminal on the router and run /import file-name=router.rsc. The router creates the WireGuard interface, dials out to our server, and the tunnel comes up. It reconnects on its own after reboots or line drops.

  3. 3

    Connect to it from anywhere

    The router now answers on its permanent access address. Open Winbox, SSH, WebFig or RDP and connect as if you were on the local network — from the office, from home, or from a phone on mobile data.

Plans & pricing

Priced per router. Billed monthly. No lock-in.

Every plan starts with a 7-day free trial — no credit card required. Invoices are issued per router and settled by M-Pesa.

Access

Remote access and the router management toolkit.

KES 300/ router / month

The plan most operators start on.

  • Permanent access address
  • Winbox, SSH, WebFig, RDP
  • Router management tools
  • Site-to-site VPN included
  • Offline WhatsApp alerts

Dedicated IP

A dedicated address for one router. An add-on to any plan.

+KES 1,500/ router / month

Added on top of Access or Route.

  • One address reserved for one router
  • Useful for allow-lists and fixed integrations
  • Does not change when the tunnel reconnects

Site-to-site VPN

Connect every branch LAN into one private network.

Freewith every Access router

Included, not an extra line item.

  • Every branch LAN reaches every other
  • Routes pushed to each router automatically
  • Drag routers into a network from the dashboard
  • WireGuard and SSTP mixed in one network

How billing works. Pricing is per router, per month, in Kenyan Shillings, and is invoiced monthly. Payment is by M-Pesa. The 7-day free trial needs no credit card — if you do not continue, the tunnel is simply closed and the router returns to its original state.

Site-to-site VPN

Every branch LAN reaches every other branch LAN.

Put several routers into one network and MUA VPN connects their local networks to each other. A till in Mombasa reaches a server in Nairobi; a printer in one office is visible from another. Routes are pushed to each router automatically, so there is no route table to maintain by hand.

Three branch LANs connected through the MUA VPN server Three branch networks each connect over an encrypted WireGuard tunnel to the MUA VPN server. Every branch can reach every other branch. MUA VPN server hub · 10.66.0.1 Branch LAN 1 192.168.10.0/24 Branch LAN 2 192.168.20.0/24 Branch LAN 3 192.168.30.0/24 encrypted WireGuard tunnels

Each branch dials out once. The server joins the tunnels into one private network.

Drag routers into a network

Create a network in the dashboard and add routers to it. Adding or removing a branch is a drag, not a config change on every device.

Routes pushed automatically

When a branch joins, the other routers receive the routes they need. When it leaves, those routes are withdrawn. No manual route tables.

WireGuard and SSTP together

A single network can mix WireGuard and SSTP tunnels, so you can include a router or machine that cannot run WireGuard.

Router management tools

Once you are in, you can actually run the network.

MUA VPN is not only a tunnel. The dashboard gives you the day-to-day tools an ISP or network operator needs, so you are not writing the same scripts for every router.

PPPoE subscribers

Add, disable and search subscribers. See who is online right now, drop a live session, and set an expiry date — all without opening a terminal.

Expiry & renewals

A subscriber switches off automatically when their period lapses, and switches back on the moment they renew. No late-night manual disabling.

Hotspot vouchers

Bulk-generate voucher batches: plain cards, scan-to-connect QR codes, or printable posters. Print, hand out, and let the codes do the work.

Config backups

A copy of each router's configuration is taken every day, automatically. If a change goes wrong, restore any earlier version.

Monitoring & alerts

Know the moment a device goes offline.

A router that stops answering is usually the first sign of a power cut, a dead link, or a site problem. MUA VPN watches the tunnel and tells you on WhatsApp the moment a device drops off — and again when it comes back.

  • A WhatsApp alert the moment a device goes offline
  • A second notification when it reconnects
  • Last-seen time for every device
  • Connection history, so you can see how often a line drops
WhatsApp alert

MUA VPN — alert

Device Branch LAN 3 (Mombasa) went offline at 14:22.

Last seen 14:21. Tunnel down.


MUA VPN — recovery

Device Branch LAN 3 (Mombasa) is back online at 14:31.

Downtime 9 minutes. Tunnel restored.

Example alert format. Names and times are illustrative.

Security

Encrypted in transit. Closed to the public internet.

WireGuard encryption

All tunnel traffic is carried inside WireGuard. Keys are unique per device, and only the server and the device hold them.

Management ports closed

On routers with a static public IP, risky management services — SSH, Telnet and the RouterOS API — are blocked from the public internet by default.

No inbound exposure

Because the router dials out to us, you do not have to expose a management port to the internet to get remote access.

Who it is for

Built for people who run networks.

ISPs & network operators

Manage customer routers and your own sites without ordering a public IP for every one. Keep PPPoE subscribers, expiry and hotspot vouchers in one place.

No public IP / Starlink

Sites on Starlink, fixed wireless or a shared ISP line get a stable access address that does not change when the carrier's address does.

Businesses with many sites

Connect branch LANs into one private network so tills, servers and printers at different locations can talk to each other.

Remote workers & servers

Reach a Windows or Linux machine in the office or at a remote site with RDP or SSH, even when it sits behind a NAT you do not control.

FAQ

Questions operators actually ask.

It gives your router or machine a permanent address on our server. The device opens an outbound WireGuard tunnel to us and keeps it open. Because the connection starts from your side, it works even when nothing can connect to you from the internet — and because the tunnel is always there, you always have the same address to connect to.

No. That is the point. MUA VPN works on the connection you already have, including CGNAT, Starlink, fixed wireless and shared fibre plans. You do not need a static IP, and you do not need to ask your ISP for anything.

MikroTik routers running RouterOS v7 or later, and Windows or Linux machines that can run WireGuard. For site-to-site networks you can also include devices using SSTP, so a router or machine without WireGuard support can still join.

A consumer VPN is built to hide one person's browsing. MUA VPN is built to reach and manage devices. You get a fixed address per device, router management tools, site-to-site networking, offline alerts and automatic configuration backups — the things an operator needs to run a network, not just browse through a tunnel.

Route mode sends the router's whole traffic through our server instead of only using the tunnel for management. It is for the awkward cases where specific sites or streaming services fail while everything else works. You can switch it on and off from the dashboard, and there is an automatic safety check that reverts the change if it is not actually helping. Route mode needs RouterOS v7 or later.

Pricing is per router, per month, in Kenyan Shillings, and you are invoiced monthly. Payment is by M-Pesa. Access is KES 300 per router per month, Route is KES 5,000 per router per month, and a Dedicated IP is a KES 1,500 per router per month add-on. Site-to-site VPN is included free with every Access router. Every plan starts with a 7-day free trial and no credit card.

Yes. Everything that travels over the tunnel is carried inside WireGuard, which uses modern cryptography and per-device keys. In a site-to-site network, traffic between branch LANs is carried inside those tunnels too. On routers that do have a static public IP, we also block SSH, Telnet and the RouterOS API from the public internet by default.

The tunnel reconnects by itself once the line is back. The device keeps the same access address, so nothing on your side needs to change. While it is down you get a WhatsApp alert, and a second notification when it returns.

Yes. Every router is its own line on your invoice, at the same per-router price. You can add routers at any time, and put them into a site-to-site network if you want their LANs to reach each other.

A device we support, working internet, and access to configure it — for a MikroTik router, that means the ability to open a terminal in Winbox, WebFig or SSH. We generate the script for you; you import it in one command. The full process is in the setup guide.

Give your routers an address you can always reach.

Start with a 7-day free trial. No credit card, no public IP to order, no ISP ticket to raise. Add one router, or a hundred.