How to monitor a MikroTik router behind CGNAT without opening ports
Push monitoring turns the check around: the router calls out over HTTPS, so it works behind CGNAT with nothing opened in the firewall. Here is how the free Tanod Monitor does it with one RouterOS script, what it alerts on, and its limits.
The problem
A router behind CGNAT has no public address, so an outside monitor cannot ping it, and opening ports is not possible or not wise. The fix is to turn the check around: the router reports to a monitor over HTTPS (push monitoring), and the monitor alerts you when the reports stop or look wrong. Nothing is opened in the router firewall.
How it works with Tanod Monitor
Tanod Monitor is free and needs no account or email. Creating a MikroTik monitor gives you a secret manage link (shown once; keep it private, anyone with it controls your monitors) and a RouterOS script with the push token inside.
You paste the script into a RouterOS terminal. It creates a script named tanod-watch and a scheduler that runs it every 1 or 5 minutes. The script sends one HTTPS POST of JSON with /tool fetch to https://tanod.dev/monitor/m/<token>. It works on RouterOS v6 and v7.
What the script reports
Identity and uptime are always sent. Where the router has them, it also sends CPU load, free and total memory, temperature and voltage, the running state of up to 24 interfaces, PPPoE and hotspot user counts, and the WAN IP. Sensors, PPPoE, hotspot and the WAN lookup are each wrapped so that a missing value is just left out instead of breaking the script. Router-supplied text (identity, interface names) is escaped for JSON.
What is alerted
A monitor goes down after period plus grace without a report (defaults: 5 minutes plus 120 seconds). It also opens an incident, and alerts, when:
- CPU is above the limit (default 90 percent)
- temperature is above the limit (default 75 C)
- free memory is below the limit (default 10 percent)
- an interface you watch is down or missing from the report
- the router reboots (uptime went down)
- the WAN IP changes
Alerts are sent when an incident opens and when it recovers, not repeatedly. The same monitor and incident kind does not alert again within 10 minutes.
Where the alerts go
ntfy and webhook work now. Telegram is coming soon and is not available yet, so do not plan on it. A group can have up to 5 alert channels. ntfy takes a topic URL such as https://ntfy.sh/your-topic. A webhook must be HTTPS on port 443 and receives JSON with text, event and monitor. You can add channels in the dashboard, or with the manage token:
curl -s -X POST https://tanod.dev/monitor/v1/channels \
-H "Authorization: Bearer $MANAGE_TOKEN" \
-H 'content-type: application/json' \
-d '{"kind": "ntfy", "target": "https://ntfy.sh/your-topic"}'Set it up
1. Open tanod.dev/monitor, choose "MikroTik router (push)", name it and pick how often the router reports. 2. Save the manage link. 3. Pick your RouterOS version and copy the script. 4. On v7, import a CA bundle into /certificate first (the script has a comment at the top), because it sets check-certificate=yes. 5. Paste the script into a terminal on the router. 6. Add an ntfy or webhook channel in the dashboard.
Honest limits
On RouterOS v6 the script does not set check-certificate, which behaves differently across 6.x releases, so the request is HTTPS but the server is not authenticated until you add a CA bundle and the setting yourself. The monitor sees only what the router sends; if the router is up but its uplink is down, it simply stops reporting, which is the alert you get. The status page is optional and off by default. The checks are a monitoring aid, not a guarantee of detection.
Free tier
Free, no account, no email. Up to 20 monitors per group, reports as often as every minute (5 minutes by default), up to 5 alert channels, and about a day of history per monitor. A group that is never opened and never receives a report for 30 days is deleted, with no warning. Keep the manage link: it cannot be recovered.
Price
Free. There is nothing to pay and no x402 step: this is not a paid API route, and there is no MCP tool for it. Create a monitor at tanod.dev/monitor.
All endpoints →Related: Winbox port 8291 open to the internet?. Related guides: Free uptime monitoring without an account, SPF, DMARC and DKIM check API, Whois (RDAP) lookup API. Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.