Features

Every branch, every employee, one network

SecuryTik Overlay & VPN Automation

A self-hosted VPN hub for MikroTik branches and remote staff: routing, policies, DNS, monitoring and router management in one panel, on one VPS you own.

Network

One routed network, no NAT inside

Your VPS becomes the hub. Every branch and every remote user reaches every other by its real address.

Sova · Network
One routed network, no NAT inside — Sova panel

Hub-and-spoke WireGuard

  • One tunnel per branch, dialled OUT from the branch — works behind NAT, CGNAT and 4G
  • A port per site (51000 + site number); nothing to open at the branch
  • No NAT between sites: logs, cameras and servers see real source addresses

L2TP/IPsec backup

  • A second tunnel per branch, used automatically when WireGuard is blocked or down
  • Failover in about 20 seconds, and back again by itself
  • The dashboard shows which sites run on the backup path

OSPF routing

  • Branches announce their networks; the hub learns and shares them
  • A new branch is learned by every other branch without touching them
  • Networks the branch admin adds by hand are shared too — per site, with a toggle

Route checks

  • A branch may only announce addresses inside its own block
  • Anything else is rejected at the hub and raises an alert — no route hijacking
  • The Routes page shows accepted, backup and rejected networks with path and next hop
Sites

A branch in two minutes

Name it, tick the networks it needs, paste one line into the router.

Sova · Sites
A branch in two minutes — Sova panel

Derived addressing

  • Site N owns 10.N.0.0/16; network types sit at the same third octet everywhere
  • Servers are 10.1.1.x at site 1 and 10.2.1.x at site 2 — nothing to plan, nothing to collide
  • One port per network, from ether2 upwards, with DHCP — no VLANs needed

Paste-ready RouterOS script

  • One line to paste: the router fetches its script from the hub (single use, 24 hours)
  • Checks the router first; never touches the WAN or the default route
  • Safe to paste again at any time: everything tagged SOVA is replaced

Apply to router

  • Managed branches get changes pushed over their tunnel — no re-pasting
  • Add a network, move a port, rotate keys: one button
  • Enable, disable, edit and delete from a SAMM-style list with bulk actions
Remote access

Employees connect from anywhere

WireGuard app or the L2TP/IPsec client built into every phone and laptop.

Sova · Remote access
Employees connect from anywhere — Sova panel

Two profiles

  • Corporate: only company networks go through the VPN
  • Full passthrough: all traffic leaves through the hub, with the hub's IP
  • A fixed VPN address per user, so policies and logs know who it is

Per-user access

  • The whole fleet, one site, one network type everywhere, or one network at one site
  • Expiry dates; disabling disconnects at once
  • New key and password in one click

Easy handover

  • QR code for phones, .conf for computers
  • Copy or export the WireGuard config and the L2TP details from the list or the user page
  • Step-by-step client notes in the docs
Policies

Who reaches what — including apps

Every site reaches every site by default. Rules are checked top to bottom, firewall style.

Sova · Policies
Who reaches what — including apps — Sova panel

Enforced on the hub

  • All branch-to-branch traffic crosses the hub, so a branch cannot bypass a rule
  • Allow or deny by protocol and port, one way or both
  • A new deny also cuts connections that are already open

Several sources and destinations

  • Pick sites, networks, remote-user groups or addresses — as many as a rule needs
  • Drag rules into order; the first match wins
  • Search, filter, export, bulk enable/disable

App & website blocking

  • Block TikTok, Instagram, games, streaming… for chosen networks
  • Enforced on the branch router, where the branch's own internet is
  • Sova switches the app on in that router's filter for you
Manager

Every branch router, from one screen

The MikroTik Manager from SAMM, over the tunnels — no public IP, no port forwarding.

Sova · Manager
Every branch router, from one screen — Sova panel

Health & control

  • Model, RouterOS version, CPU, memory, uptime, interfaces live
  • Time zone, NTP, DNS, reboot, RouterOS updates
  • Ping and traceroute from the router or from the hub

Traffic history

  • Interface traffic for every managed router, kept 30 days
  • Traffic per app and website, with totals for any window
  • Know what each branch uses without logging in to it

Bulk actions

  • Tick routers and set time zone, NTP or DNS, update, back up or reboot
  • A result per router
  • Website & app filter per router, and blocks per network
Monitoring

Know before the branch calls

Latency, loss and traffic for every tunnel, checked every 30 seconds.

Sova · Monitoring
Know before the branch calls — Sova panel

Charts & dashboards

  • Dashboard blocks you drag, resize and save as several dashboards
  • Windows from 10 minutes to 7 days, per site or for all
  • Remote users online, with their traffic

Alerts

  • Site down, on backup path, foreign routes, router unreachable, hub apply failed
  • “I am on it” and quiet for an hour or a day — the SAMM alert log
  • Every alert resolves by itself when the problem clears

Notification center

  • Telegram, email and WhatsApp Cloud API
  • Choose which events go to which channel
  • An outbox with every message sent or failed
DNS

Names instead of numbers

The hub answers for your internal zone; everything else goes to public DNS.

Sova · DNS
Names instead of numbers — Sova panel

Automatic names

  • router.. and gw-.. for every branch
  • Branch DHCP and remote users get the hub as DNS
  • Works over either tunnel

Your own records

  • erp.hq.corp → 10.1.1.10 in one pop-up
  • Automatic and manual names in one searchable list
  • Export to CSV or Excel
Operations

Built to be run by a team

The same administration tools SAMM customers already know.

Sova · Operations
Built to be run by a team — Sova panel

Admins, roles & audit

  • Per-area view / edit permissions; Super Admin, Manager, Monitor
  • Every change in the audit log — who, when, from where
  • Password recovery by email, and a reset tool for lockouts

API & webhooks

  • REST API with scoped tokens: sites, remote users, policies, DNS, stats, devices
  • Signed webhooks for site, user and alert events
  • Interactive reference at /api/v1/docs

Backup, updates, Cloudflare

  • Scheduled backups with retention; restore in one click
  • Signed updates from the panel — tunnels keep running
  • HTTPS on your own domain through Cloudflare Tunnel

Start with two branches, free.

One command on a fresh Ubuntu VPS. Every paid plan is free for its first month.