If you run Antminers at home, in a container or at a hosted site, you have probably hit the same wall: your miners sit behind a router, and reaching them from outside means port forwarding, a VPN or a static IP. This guide walks through monitoring and controlling a whole fleet from anywhere in about two minutes of setup β with none of those. It also covers what to watch once you are connected, the alert rules that catch real failures, and the tricky network situations (CGNAT, Starlink, 4G/5G) where traditional remote access simply does not work.
Why port forwarding is the wrong answer
An Antminer's web interface was never designed to face the internet. Every stock unit ships with the same default credentials (root/root), the embedded web server receives security patches rarely if ever, and scanning botnets probe the entire IPv4 space for exposed miner interfaces continuously β put one on a public port and the first hostile login attempt typically arrives within hours. Exposed miners get their pool settings silently rewritten so someone else collects your hashrate, and that is the friendly outcome.
Even if you accept the risk, port forwarding often is not available at all. Starlink, most 4G/5G routers and a growing number of home ISPs use carrier-grade NAT (CGNAT): your router's "public" address is itself private, shared with hundreds of other customers, and no amount of router configuration will make an inbound connection reach you. VPNs solve the security problem but replace it with maintenance: a VPS to rent, WireGuard configs per device, and one more thing that breaks at 3 a.m.
The outbound-tunnel approach
AntminerTools inverts the connection. A small connector agent runs on any machine inside the farm network β a Raspberry Pi, a Windows PC that is already there, or any Linux box β and opens a single encrypted WebSocket outbound to the AntminerTools cloud. Outbound connections work everywhere: through CGNAT, Starlink, hotel Wi-Fi, anything that can load a web page. Your dashboard talks to the cloud, the cloud talks down the tunnel, and the agent relays requests to miners on the local network.
The security consequences are worth spelling out. Nothing inside your farm listens for internet connections, so there is nothing to scan, nothing to brute-force and no attack surface to patch. Miner credentials are used only inside your LAN by the agent; the tunnel itself is TLS-encrypted and authenticated per farm. From the internet's point of view, your farm does not exist.
Setup, step by step
1. Create a farm. Sign up free, add a farm in the dashboard, and copy the one-line install command it shows you.
2. Run the agent inside the farm network. Paste the command on any always-on machine on the same LAN as the miners: a Raspberry Pi is ideal (a Pi 3 handles dozens of miners), a Windows host PC works with a downloadable installer, and any Linux server runs it as a systemd service. The moment it starts, the farm shows connected in your dashboard.
3. Scan for miners. The agent sweeps the local subnet, finds every Antminer answering on its API, and registers them with names pulled from their pool worker configuration. A 20-miner farm takes about a minute to appear.
That is the whole process β no router configuration, no static IP purchase, no VPN certificates.
What you actually see
Each miner reports its live 5-second and 30-minute hashrate, per-chain status, chip and PCB temperatures, fan speeds, power draw, efficiency in joules per terahash, firmware version, uptime and active pool with share counts β refreshed continuously while a dashboard is open. Fleet totals sit at the top: combined hashrate, total wall power, online count and the hottest unit right now. The dashboard works identically from a phone, which matters more than it sounds the first time a miner misbehaves while you are away.
Model-specific quirks are handled for you β hydro units like the S21 Hyd. report chip temperatures in a different sensor field than air-cooled units, Scrypt miners like the L7 report GH/s rather than TH/s, and the dashboard normalizes all of it.
Control, not just monitoring
Reading stats is half the job. Through the same tunnel you can reboot a hung miner, blink an LED to find a specific unit in a rack of identical machines, switch work modes (normal / sleep / turbo where the firmware supports it) and change pool configuration β from anywhere, without exposing a single port. For the times you need the actual farm PC rather than a miner, the same agent can stream its screen as a built-in remote desktop.
Alerts: the part that actually saves money
Nobody watches a dashboard all day, and downtime you notice eight hours late is revenue gone. Three rules cover the failures that actually happen, and each takes under a minute to create:
Miner offline β fires about a minute after a unit stops answering polls, with an email naming the machine. Hashrate zero β catches the classic hung-bmminer state where the miner answers its API but does no work; pair it with the auto-restart action and the platform reboots the unit for you (a ten-minute boot grace prevents false alarms while a restarted miner ramps up). High temperature β fires at 85 Β°C chip temperature, the line above which sustained operation degrades hardware; see the companion guide on preventing Antminer overheating for thresholds per model and an auto-sleep setup.
The result in practice: a miner hangs at 4 a.m., the platform notices within a minute, restarts it, confirms hashrate recovery and resolves the alert β and the only evidence in the morning is two emails and a few minutes of lost work instead of a dead shift.
Awkward networks: CGNAT, Starlink, mobile
Starlink uses CGNAT on standard plans β port forwarding is impossible, and outbound tunneling is the only clean option. It works unmodified. 4G/5G routers behave the same way. Double-NAT setups (ISP router feeding your own router) need no special handling either, because nothing ever connects inward. The single requirement is that the agent machine can reach the internet over HTTPS β if it can load a web page, your farm can be monitored.
Port forwarding vs VPN vs outbound tunnel
| Approach | Works behind CGNAT / Starlink | Attack surface | Setup effort | Ongoing cost |
|---|---|---|---|---|
| Port forwarding | No | Miner web UI exposed to the internet | Router config per port | Free, until an exposed miner is hijacked |
| VPN (WireGuard/OpenVPN) | Only with a rented VPS relay | VPN endpoint itself | Keys and configs per device | VPS rent + your maintenance time |
| Outbound tunnel (AntminerTools) | Yes | None listening β outbound only | One command, once | Free tier; paid plans for big fleets |
When a miner goes offline: a five-minute runbook
An offline alert tells you a unit stopped answering β here is the order that finds the cause fastest. First, check whether the whole farm went quiet: if every miner dropped at once, it is power or internet at the site, not eight simultaneous hardware failures. Second, look at the miner's last-seen time and its neighbours β the dashboard greys out stale readings so you cannot mistake old numbers for live ones. Third, try a remote reboot; a hung controller board recovers from a power cycle in two to four minutes, and if hashrate returns, the alert resolves itself and you are done. If the unit stays dark, blink the LED on a neighbouring machine so whoever is physically at the site walks to the right rack β and check the obvious suspects in person: tripped breaker, seated network cable, PSU fan. The pattern matters too: the same unit dropping daily at the hottest hour is a cooling problem wearing an offline costume; see the overheating guide for that path.
Frequently asked questions
Does the agent need to run on each miner? No β one agent per site covers every miner on that network. It runs on a separate always-on machine, not on the miners themselves.
What happens if the agent machine goes down? The farm shows disconnected and its miners are marked offline within a couple of minutes, so an agent-host failure is itself something you get alerted about.
Does this work with Braiins OS, LuxOS or VNish? Stock Bitmain firmware is fully supported; third-party firmwares that keep the standard API surface generally report stats correctly.
How much bandwidth does it use? Polling a fleet uses a few kilobytes per miner per cycle β irrelevant on any connection, including metered Starlink.
Is my miner login sent to the cloud? Credentials are used by the agent inside your LAN to talk to miners; the tunnel outward carries stats and commands over TLS.
Get your fleet online tonight
Create a free account, run one command on any machine at the farm, and your Antminers are on your phone before your coffee cools β no ports opened, no VPN built, no static IP rented. The free tier covers small setups; see pricing for larger fleets, and the docs for deeper setup detail per platform.