Secure Remote Access Links for MikroTik Devices
Цей контент ще не доступний вашою мовою.
Summary When you open a device remotely, MKController creates a temporary link (https://…remote.mkcontroller.net). With the secure access URL on, that link can’t be forwarded: it only opens on the network where it was created, stays tied to the first browser that opens it and expires after 30 minutes.
Remote access links are powerful — they open a router’s management interface. The secure access URL makes sure the person who opens the link is the person who asked for it.
How remote access links work
Section titled “How remote access links work”When you click to access a device remotely — the WebFig interface of a MikroTik router, for example, even behind CGNAT — MKController generates a unique, temporary link that opens the device through the platform. Each click creates a new link.
What the secure access URL changes
Section titled “What the secure access URL changes”The option is off by default and available on every plan. When a company turns it on:
- Same network on the first open. The link only opens, the first time, on the same network where it was generated.
- One browser per link. The first browser that opens the link keeps it. Any other browser is refused — even with the link in hand.
- IP changes are fine. If the IP changes during use (Starlink, mobile networks), access continues in the same browser.
- 30 minutes, always. The link lasts 30 minutes. After that, generate a new one from the platform.
Turn on the secure access URL
Section titled “Turn on the secure access URL”- Go to Settings → Security (company administrators only).
- Open the Remote access tab.
- Switch Secure access URL on.
The confirmation tells you when it takes effect: it applies to links opened from now on, and a link already in use can take up to 5 minutes to follow the new rule. Turning it off works the same way.
What people see when a link is refused
Section titled “What people see when a link is refused”A refused link opens a page explaining why, in Portuguese and English, with a button to talk to support:
| The page says | Why | What to do |
|---|---|---|
| This secure access link was already opened in another browser | Someone else — or another browser on the same computer — opened the link first. | Generate a new link and open it in the browser you will use. |
| This secure access link only opens on the network it was generated from | The first open came from a different network. | Generate the link from the network where you will use it. |
| We couldn’t verify this access right now | The access couldn’t be confirmed at that moment. | Generate a new link on the same network and try again. |
When to keep it off
Section titled “When to keep it off”The secure access URL assumes that the person who generates the link is the person who opens it. Keep it off if your team works differently, for example:
- Links created through the MKController API by one system and opened by people elsewhere — the network that counts is the one that created the link.
- People who generate the link on one network and open it on another — at the office VPN and then on a phone over 4G, for instance.
Frequently asked questions
Section titled “Frequently asked questions”Does it work with Starlink or mobile connections?
Section titled “Does it work with Starlink or mobile connections?”Yes. The network is only checked on the first open. After that, access keeps working in the same browser even if the public IP changes.
Can I share a link with a colleague?
Section titled “Can I share a link with a colleague?”Not with the secure access URL on — the first browser keeps the link. Each person generates their own link from the platform.
How long does a remote access link last?
Section titled “How long does a remote access link last?”30 minutes. Generate a new one from the device when it expires.
Does it affect my customers or other companies?
Section titled “Does it affect my customers or other companies?”No. It only applies to the remote access links of your company’s devices.
Next steps
Section titled “Next steps”- Single Sign-On (SSO) — sign in with Google or Microsoft Entra ID.
- Active sessions — see who is signed in and revoke access.
Didn’t find what you need? Have questions or feedback? Reach out to MKController Support.
👉 Click here to talk to us.