Installation and Configuration Guide Step-by-step instructions for installing the module, preparing the Mikrotik router, and configuring WHMCS products and servers. Setup Guide: Mikrotik Preparation and Configuration Mikrotik WireGuard VPN module WHMCS Order now | Download | Community Prerequisites RouterOS version 7 or higher is required. Access to the Mikrotik router via terminal (SSH, Winbox terminal, or WebFig terminal). Important: Enter the following commands one by one and wait for each command to complete before proceeding to the next. Step I. Check RouterOS Version Verify that your router is running RouterOS 7 or higher: system/package/print Step II. Create Root Certificate Authority Create a local CA certificate for SSL: /certificate add name=LocalCA common-name=LocalCA key-usage=key-cert-sign,crl-sign Step III. Sign the CA Certificate /certificate sign LocalCA Step IV. Create Webfig Certificate Replace XXX.XXX.XXX.XXX with the router's public IP address: /certificate add name=Webfig common-name=XXX.XXX.XXX.XXX Step V. Sign the Webfig Certificate /certificate sign Webfig ca=LocalCA Step VI. Enable SSL for the Web Interface /ip service set www-ssl certificate=Webfig disabled=no Step VII. Enable API-SSL /ip service set api-ssl certificate=Webfig disabled=no Step VIII. WireGuard VPN Server Setup Create and enable the WireGuard VPN server interface through the RouterOS interface. You can do this via Winbox or WebFig: Navigate to WireGuard section Click Add New (+) Set the interface name (e.g., wireguard1) Set the Listen Port (e.g., 13231) Enable the interface mikrotik-wireguard-setup.png Step IX. Configure Firewall, NAT and Routing Important: Please be aware that to ensure proper functionality of VPN connections, it is essential for you, as an administrator, to correctly configure the Mikrotik router. This entails configuring NAT, Firewall, routing, and all the required settings for VPN to operate correctly. Example NAT masquerade rule (adjust to your network): /ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade Example firewall rule to allow WireGuard traffic: /ip firewall filter add chain=input protocol=udp dst-port=13231 action=accept comment="Allow WireGuard" Next Steps After completing the Mikrotik preparation, proceed to Add server (router Mikrotik) in WHMCS. WHMCS Installation and Update Mikrotik WireGuard VPN module WHMCS Order now | Download | Community System requirements Requirement Minimum WHMCS 8.x+, 9.x+. PHP 7.4, 8.1, 8.2, 8.3, 8.4 ionCube Loader v15+ Mikrotik RouterOS 7.x+ Note: The module uses ionCube encoding. Make sure ionCube Loader is installed and active on your server. Installation Note: The module now uses ionCube 15, which provides universal out-of-the-box support for all encodings. All versions can be found at this link: https://download.puqcloud.com/WHMCS/servers/PUQ_WHMCS-Mikrotik-WireGuard-VPN/ Older module versions for WHMCS 8 are available in the archive directory: https://download.puqcloud.com/WHMCS/servers/PUQ_WHMCS-Mikrotik-WireGuard-VPN/archive/ Download the latest version from the PUQ download page: wget https://download.puqcloud.com/WHMCS/servers/PUQ_WHMCS-Mikrotik-WireGuard-VPN/PUQ_WHMCS-Mikrotik-WireGuard-VPN-latest.zip Unzip the archive: unzip PUQ_WHMCS-Mikrotik-WireGuard-VPN-latest.zip Copy the puqMikrotikWireGuardVPN directory into your WHMCS installation under modules/servers/: cp -r puqMikrotikWireGuardVPN /path/to/whmcs/modules/servers/ The resulting directory structure should look like: modules/ servers/ puqMikrotikWireGuardVPN/ puqMikrotikWireGuardVPN.php hooks.php lib/ templates/ lang/ ... Update The update process is identical to the installation: Download the latest archive from the download page: wget https://download.puqcloud.com/WHMCS/servers/PUQ_WHMCS-Mikrotik-WireGuard-VPN/PUQ_WHMCS-Mikrotik-WireGuard-VPN-latest.zip Unzip the archive: unzip -o PUQ_WHMCS-Mikrotik-WireGuard-VPN-latest.zip Replace the existing puqMikrotikWireGuardVPN directory in your WHMCS installation: cp -r puqMikrotikWireGuardVPN /path/to/whmcs/modules/servers/ Warning: When updating from v2.x to v3.x+, product reconfiguration is required due to the new settings storage format. Product Configuration Mikrotik WireGuard VPN module WHMCS Order now | Download | Community Add new product to WHMCS Log in to your WHMCS Admin Area. Navigate to System Settings → Products/Services → Create a New Product. Fill in the product details (name, description, pricing). Go to the Module Settings tab. Select PUQ Mikrotik WireGuard VPN from the Module Name dropdown. Enter your License key in the corresponding field. Configure the remaining module parameters. Click Save Changes. product-configuration.png Configuration parameters Parameter Description Default License key Pre-purchased license key for the module. WireGuard Interface Name of the WireGuard interface on the Mikrotik router (must be pre-created) wg1 Comment prefix Prefix added to VPN peer and queue comments on Mikrotik whmcs Upload (Mbs/s) Upload bandwidth speed limit in Mbps 5 Download (Mbs/s) Download bandwidth speed limit in Mbps 5 Allowed IPs IP ranges allowed to route through the VPN tunnel 0.0.0.0/0, ::/0 DNS Servers DNS servers to use when connected to VPN (comma-separated) 8.8.8.8, 1.1.1.1 Persistent Keepalive Interval for sending keepalive packets (seconds) 25 seconds Disable statistics collection When enabled, traffic statistics will not be collected and the statistics page will be hidden from the client area Unchecked Save history (days) Number of days to keep usage statistics in WHMCS (minimum 32 days) 32 Link to instruction URL to setup instructions (displayed in client area as "User manual" button) Empty Custom HTML Custom HTML content for WireGuard protocol (displayed in client area) Empty Allowed IPs examples: 0.0.0.0/0, ::/0 — route all IPv4 and IPv6 traffic through VPN (full tunnel) 10.0.0.0/8, 192.168.0.0/16 — route only specific networks (split tunnel) Recommended: Set "Link to instruction" to https://www.wireguard.com/install/ — the official WireGuard client downloads page. product-config-mikrotik-bandwidth.png product-config-wireguard.png product-config-history.png product-config-client-area.png Metric Billing The module supports usage-based billing through WHMCS Metric Billing. Two metrics are available: Bandwidth Usage Download (GB) — monthly download traffic in gigabytes Bandwidth Usage Upload (GB) — monthly upload traffic in gigabytes To enable metric billing, go to the product's Metric Billing section and toggle the desired metrics ON, then click Configure Pricing to set the per-GB price. metric-billing.png metric-billing-download.png metric-billing-upload.png Add Server (Router Mikrotik) in WHMCS Mikrotik WireGuard VPN module WHMCS Order now | Download | Community Navigate to System Settings > Servers > Add New Server in WHMCS admin area. Step 1: Name and Hostname Name — a descriptive name for your convenience (e.g., "Mikrotik VPN Router 1") Hostname — the hostname that resolves to your Mikrotik router's IP address (e.g., vpn.mydomain.com). You can also use a dedicated domain. The important thing is that the chosen hostname resolves to the IP address of the Mikrotik router in your DNS. Step 2: Assigned IP Addresses In the Assigned IP Addresses field, enter a list of IP addresses that will be issued to VPN clients — one IP per line. These IPs will be assigned to WireGuard peers as their tunnel addresses. The module automatically allocates the first available (unused) IP from this pool for each new service. whmcs-server-ips.png Step 3: Server Details Select the "PUQ Mikrotik WireGuard VPN" module from the Module dropdown Enter the correct username and password for the Mikrotik router Set the port (default: 443 for HTTPS REST API) Check the Secure checkbox if using HTTPS (recommended) whmcs-server-details.png Step 4: Test Connection Click the "Test Connection" button to verify that WHMCS can communicate with the Mikrotik router via REST API. A successful connection will confirm that: The Mikrotik router is reachable The credentials are correct The REST API is enabled and responding Next Steps After adding the server, proceed to Product Configuration in WHMCS.