Manual
Configurator manual
How to get from an empty screen to a working configuration, chapter by chapter.
Getting started
How a network works
What a router actually does
A router has two sides and one job: decide, for every packet, where it goes next.
Switching and routing
A switch delivers inside one network, a router delivers between networks. Almost everything follows from that.
Addresses and prefixes
Subnetting without the arithmetic panic: a prefix says how much of the address is the network.
NAT and ports
Why a household of thirty devices looks like one visitor from the outside, and what that costs you.
How DNS works
Computers route on numbers and people remember names. DNS is the desk in between.
Wi-Fi as radio
Wi-Fi is radio, and every disappointment with it comes from something radio has always done.
Setting it up
Drawing
Bringing an existing configuration
After generating
Worked examples
Example: replacing the ISP router
One router, internet, Wi-Fi and a firewall that is closed. The ordinary case.
Example: an office with VLANs, a switch and access points
Router, switch and two access points, with VLANs for office, guests, IoT and management.
Example: a guest network that is actually separate
Internet for visitors, no access to your NAS, your cameras or your router.
Example: two locations with a tunnel
Connecting two locations, with addresses that do not get in each other's way.
Several devices and locations
Two offices, one design
Two offices with the same VLAN numbers, an address range of their own, and a tunnel in between.
A head office with five branches
One head office, five branches that only talk to the hub, and numbering you can still read a year later.
Switches in a ring: RSTP
A ring of switches gives you a spare path, as long as RSTP knows which switch is in charge.
Two routers as one gateway (VRRP)
A second router that takes over the gateway address, and an honest list of what does not move with it.
One CAPsMAN for several buildings
One controller for the wifi of several buildings: when that is sensible and when you install two.
Stretching layer 2 or routing
One subnet across two locations, or two subnets with a route between them. The difference is bigger than it looks.
A numbering plan that survives growth
Numbering you can still read in three years and ten locations without opening a spreadsheet.
Replacing a live network, device by device
From old to new in steps you can undo one at a time.
Rolling out twenty branches
Design one branch properly and repeat it nineteen times, without collecting nineteen deviations.
OSPF between locations
Once there is more than one way to a site, something has to choose. That is the moment for OSPF.
Three sites in a mesh
Three tunnels instead of two, and the question of whether that extra path earns its upkeep.
Two providers at every site
A second line per branch is quick to draw; the question is what exactly takes over, and when.
The same guest network everywhere
One guest network, ten branches, and the question of where that traffic leaves the building.
Telephones across locations
One VLAN for the handsets, and the sober limits of priority on a line you share with everyone else.
Cameras at several locations
Cameras are cheap, bandwidth over a tunnel is not. Do the arithmetic first, build afterwards.
A management network across locations
The same VLAN number everywhere, a range of its own per location, and a way in that keeps working when the rest does not.
Two cables between two switches
Two cables side by side rarely give twice the speed, and they do cost a piece of handwork.
Several buildings with fibre between them
Four buildings, fibre between them, and one question that decides everything: do you route per building or not.
Two tunnels between the same locations
Building two tunnels takes a minute. Deciding which one is the spare is not done for you.
Documenting a network of several locations
The question is not whether you understand it, but whether your successor understands it in a year without calling you.
Every part in detail
System and time
Name, password, clock, logging and updates: the lines every script needs.
Management access
Which services are open, from where, and how not to lock yourself out.
Bridge and ports
Which ports form one network, and what else you set on them.
Bonding and LACP
Several cables acting as one interface, for throughput or for redundancy.
PoE-out per port
Power over the network cable, set per port.
WAN: the connection to the internet
How your router gets online, and which fields on that page actually matter.
Several uplinks: failover and load balancing
Adding a second line, and choosing between taking over and sharing the load.
Provider presets
Picking your provider fills in the first uplink. What is and is not included.
LAN and DHCP
Your router's own address, and what it hands out to your devices.
VLANs
Several separated networks over the same cables, and which port carries what.
Setting up Wi-Fi
SSIDs, security, bands and VLANs, and why your device runs one Wi-Fi package rather than the other.
Channels, width and power
Bands, channel width, transmit power and DFS, and why wider is not always faster.
CAPsMAN
One place holding SSIDs, passphrases and VLANs, and access points that fetch their settings from it.
Firewall and NAT
The default rules, why they sit in that order, and what you add to them.
Opening a port
Reaching a device inside from the outside, and when you had better not.
DNS
The router as resolver for your network, and who sits above it.
IPv6
A prefix from your ISP, a /64 per network, and a firewall that really has to be there.
WireGuard
Encrypted tunnels with keys your browser generates and a ready-made client configuration.
VPN for individual users
Getting in with the built-in VPN client of a phone or laptop, without installing an app.
Tunnels between locations
GRE, IPIP, EoIP and VXLAN: two networks joined, routed or as the same layer 2 network.
QoS and bandwidth
Queues that decide who waits when the line is full, and what they cannot fix.
Static routes and policy routing
A route to a network that does not sit behind your default gateway, and traffic that needs another exit.
OSPF
Routers telling each other which networks they have, instead of a list of static routes you maintain.
BGP
A session with your transit or another party, set up to the point where filters become hand work.
The hotspot: a login page for visitors
Visitors only get internet after they log in, with their own account and their own limit.
The PPPoE server and RADIUS
Your router as the provider: every customer logs in with their own account and gets their own address.
VRRP: two routers, one gateway address
When one router fails the other takes over the same gateway address, with nothing to change on your clients.
Netwatch and monitoring
Watch an address and act when it goes down, without a monitoring system being involved.
Containers on RouterOS
A small application alongside RouterOS on the same device, if your hardware can carry it.
Services and tools
Everything a router can do besides routing, and which of it belongs in a base configuration.
MTU and jumbo frames
The largest packets that fit through, and what happens when they just do not.
Recipes
Recipe: reaching a camera or doorbell from outside
See the footage from your phone, without hanging the camera on the internet.
Recipe: a NAS reachable at home and nowhere else
Your files from the sofa, nothing from the internet.
Recipe: IoT devices in a network of their own
Give smart devices their own corner, without breaking casting and discovery by accident.
Recipe: a printer usable from several VLANs
Print from the office, the laptop and the phone, without giving up the separation.
Recipe: reaching home or the office from the road
From your phone or laptop into your own network, with WireGuard and a client configuration from the tool.
Recipe: LTE as a backup line
When the fixed line drops, the SIM takes over, and you knew beforehand that it would.
Recipe: fixed public IP addresses
A block of fixed addresses on the WAN, and a server that gets one of them.
Recipe: keep phone calls clear when the line is busy
A VLAN of its own for the phones and a queue that gives voice priority.
Recipe: putting limits on the guest network
Visitors get internet, but not your whole line and not your network.
Recipe: guest Wi-Fi with a login page
A captive portal for guests, on its own VLAN, away from the office network.
Recipe: Wi-Fi in a warehouse or large building
Coverage in a large building: draw first, drill second, measure third.
Recipe: Wi-Fi that keeps working as you walk
One SSID through the whole building, and a phone that follows you without dropping the call.
Recipe: a camera network
Cameras on their own VLAN, an NVR that may reach them, and nobody else.
Recipe: television from your ISP (IPTV)
Television over multicast: the IGMP proxy on the WAN and IGMP snooping on the bridge.
Recipe: a server reachable from the internet
Reachable from outside and nowhere else: a server in its own segment.
Recipe: a backup routine you actually keep up
Four files per site, one habit before every change, and a test you genuinely run.
Recipe: a school or association building
Three networks, coverage in every classroom, and a setup that makes sense without you.
Recipe: Wi-Fi for a campsite or holiday park
Many access points, a login page, and a fair share of a line that is never big enough.
Recipe: AdGuard Home or Pi-hole in a container
A DNS filter next to RouterOS on the same device, with an honest answer about when that is a good idea.
Recipe: knowing before your customer calls
Four things on the router itself, and an honest line where a monitoring system takes over.
Per model
hAP ax³
Five ports, 2.5 Gbit on the WAN side and Wi-Fi from the new wifi package.
hAP ax²
Five gigabit ports and Wi-Fi from the new wifi package, in the smaller case.
hAP ac²
The workhorse with two Wi-Fi packages on v7 and two traps worth knowing first.
hEX (RB750Gr3)
Five gigabit ports, no radios: the small wired router.
hEX S (RB760iGS)
The hEX with an SFP port and PoE-out: small, wired, a little more of it.
RB5009
Eight gigabit ports, a 2.5 Gbit WAN and a 10 Gbit SFP+ cage in a metal case.
L009 (L009UiGS-RM)
Eight gigabit ports, a 2.5 Gbit SFP and PoE-out, in a rack-mount case.
RB4011 (RB4011iGS+RM)
Ten gigabit ports and a 10 Gbit SFP+ cage: the router for when you run out of sockets.
CCR2004-16G-2S+
Sixteen gigabit ports, two 10-gigabit SFP+ cages and memory enough for a full routing table.
CRS326-24G-2S+RM
Twenty-four gigabit ports and two 10-gigabit SFP+ cages, as a RouterOS switch at the bottom of your rack.
CRS328-24P-4S+RM
Twenty-four gigabit ports with PoE-out and four 10-gigabit SFP+ cages, running RouterOS.
cAP ax
Ceiling access point with two radios, PoE-in on one port and PoE-out on the other.
wAP ax
Access point with two radios and one gigabit port, powered over that same cable.
Chateau 5G ax R17
Router with a 5G modem, five ports including one at 2.5 Gbit, and dual-band Wi-Fi.
CHR (Cloud Hosted Router)
RouterOS as a virtual machine: you decide how many interfaces it has, the licence decides how fast they may go.
hAP lite (RB941-2nD-TC)
The smallest board in the catalogue: four 100 Mbit ports, one radio, 32 MB of memory.
hEX lite (RB750r3)
Five 100 Mbit ports, no radios: the smallest wired router.
cAP lite (RBcAPL-2nD)
A small ceiling access point: one port with PoE-in, one radio on 2.4 GHz.
LtAP LTE6 kit
A router with an LTE modem and one gigabit port: internet where there is no cable.
Audience
Three radios and two gigabit ports in a standing box for the living room.
OmniTIK 5 PoE ac
Five gigabit ports, four of which can feed power, plus one 5 GHz radio.
FiberBox Plus (CRS305-1G-4S+OUT)
Four 10 Gbit SFP+ ports and one gigabit copper port: a small fibre switch.
CSS610-8G-2S+IN
Eight gigabit ports and two SFP+ ports, running SwOS: a setup sheet instead of a script.
hAP (RB951Ui-2nD)
Five 100 Mbit ports, a single 2.4 GHz radio and a small board: the plainest complete hAP.
hAP ac (RB962UiGS-5HacT2HnT)
Five gigabit ports, an SFP cage and two radios: the big hAP of the previous generation.
hAP ac lite (RB952Ui-5ac2nD)
Dual-band Wi-Fi on a small board with 100 Mbit ports: the cheapest complete MikroTik.
hAP mini (RB931-2nD)
Three ports, one radio and 32 MB of memory: the smallest device the configurator knows.
hEX PoE (RB960PGS)
Five gigabit ports of which four supply power, plus an SFP cage: the wired router that feeds your cameras.
hEX refresh (E50UG)
The same five gigabit ports as the old hEX, but on ARM with 512 MB of memory and licence level 4.
hEX S 2025 (E60iUGS)
A 2.5 Gbit WAN port, four gigabit ports and a 10 Gbit SFP+ cage in the familiar small box.
L009 with Wi-Fi (L009UiGS-2HaxD-IN)
Eight gigabit ports, a 2.5 Gbit SFP cage and a 2.4 GHz radio running the new Wi-Fi package.
RB5009UPr+S+IN (PoE)
Seven gigabit ports that all supply power, a 2.5 Gbit WAN and an SFP+ cage: the PoE version of the RB5009.
RB1100AHx4 (RB1100x4)
Thirteen gigabit ports in a 1U chassis: the rack router without fibre and without Wi-Fi.
CCR2116-12G-4S+
Thirteen gigabit ports, four SFP+ cages and 16 GB of memory: a Cloud Core Router for the rack.
CCR2216-1G-12XS-2XQ
Twelve times 25 Gbit and twice 100 Gbit: the largest router the configurator knows.
CRS309-1G-8S+IN
Eight 10 Gbit SFP+ cages in a small box: the fibre switch for a server cabinet.
CRS317-1G-16S+RM
Sixteen 10 Gbit SFP+ cages in 1U: the fibre switch for a rack full of servers.
CRS354-48G-4S+2Q+RM
Forty-nine gigabit ports plus SFP+ and QSFP+: the big access switch for a floor.
CRS310-8G+2S+IN
Eight 2.5 Gbit copper ports and two SFP+ cages: the small switch for fast desks.
BaseBox 5 (RB912UAG-5HPnD-OUT)
An outdoor box with one port and one 5 GHz radio: built for a link, not for an office.
ATL 5G R16 (ATLGM&RG520F-EU)
A small outdoor box with a 5G modem and one port: the device is the internet connection, not the network.
CCR2004-16G-2S+PC
Sixteen gigabit ports and two 10 Gbit cages, with no fan: a quiet edge router.
CCR2004-1G-12S+2XS
Twelve 10 Gbit and two 25 Gbit fibre cages, with one copper port beside them.
KNOT IoT Gateway (RB924i-2nD-BT5&BG77)
A small gateway with a modem, a radio and two 100 Mbit ports: built for sensors, not for an office.
LtAP mini LTE kit (2024)
A small LTE router with one port and one radio: internet for a place with no cable.
mANTBox 2 12s (RB911G-2HPnD-12S)
A sector antenna with the radio built in: the broadcasting end of a wireless network over distance.
PowerBox (RB750P-PBr2)
An outdoor router with four feeding ports: power and data to four devices at once.
PowerBox Pro (RB960PGS-PB)
Five gigabit ports, four of them feeding, plus an SFP cage: the larger PowerBox.
RB450Gx4
Five gigabit ports and 1 GB of memory on a bare board: a solid small router.
RB850Gx2
Five gigabit ports on an older board with a PPC processor: check which RouterOS is on it first.
RB5009UPr+S+OUT
Seven PoE ports, a 2.5 Gbit inlet and 10 Gbit fibre, in an outdoor enclosure.
RDS2216 (ROSE Data server)
Twelve fast ports up to 100 Gbit and 32 GB of memory: the heaviest device in our catalogue.
CRS106-1C-5S
Five 1 Gbit SFP cages and one combo port: a small fibre switch.
CRS112-8P-4S-IN
Eight feeding gigabit ports and four SFP cages: a small PoE switch.
CRS304-4XG-IN
Four 10 Gbit copper ports in a small box, with a gigabit port for management.
CRS305-1G-4S+IN
Four 10 Gbit SFP+ cages in a small box, with one gigabit port beside them.
CRS312-4C+8XG-RM
Twelve 10 Gbit ports in a rack unit, on a board with only 64 MB of memory.
CRS320-8P-8B-4S+RM
Sixteen 2.5 Gbit ports with PoE and four 10 Gbit cages, in a rack unit.
CRS328-4C-20S-4S+RM
Twenty SFP cages plus four 10 Gbit cages: the fibre switch for a rack.
Per provider
KPN
PPPoE over VLAN 6, with internet/internet as the login. What the preset covers and what it does not.
Ziggo
Cable, no VLAN, no login. The work is in getting the modem into bridge mode.
Odido
Fibre, formerly T-Mobile Thuis: DHCP over VLAN 300. No username, but there is a VLAN.
Delta
There is no preset for Delta. How to work out the settings yourself.
Telekom
PPPoE over VLAN 7. The preset fills in everything except your username, and that one is a puzzle.
Swisscom
Fibre with DHCP over VLAN 11. IPv6, TV and telephony are deliberately left out of the preset.
Free
Freebox in bridge mode, then DHCP without a VLAN. IPv6 is yours to set up.
A provider without a preset
The provider list is a shortcut, not a requirement. How to fill in an unknown provider yourself.
Coming from something else
Replacing your ISP router
What to note down first, what stays on the ISP box, and how to switch over without losing an evening.
Coming from a Fritz!Box
Which Fritz!Box features come back on a MikroTik, which disappear, and what to do about the telephony.
Coming from UniFi
Thinking without a controller: what CAPsMAN does for you, what you give up, and how UniFi networks and profiles map across.
Coming from pfSense or OPNsense
How a pfSense rule set maps onto RouterOS chains, and where translating it by hand goes wrong.
Moving to newer MikroTik hardware
Why your backup does not move with you, what an export does instead, and where new hardware trips you up.
RouterOS itself
WinBox, WebFig and the terminal
How you reach a MikroTik, including when its address does not match yours.
Safe mode
The difference between a mistake and a drive to the site.
Packages
What is in the base system, what you add separately, and why the version has to match.
Licence levels and CHR
What a level limits, and why the answer for a RouterBOARD is usually "nothing you will notice".
Backup and export
Two ways to save a configuration, and they are not interchangeable.
Netinstall
The last resort, and the one that always works. It also wipes the device.
Running it afterwards
Going over a device once more
The round you make after the script runs: what is open, who may get in, and what is better left alone.
Logs
What is in the log by default, how to keep it, and how to read it when something broke.
Certificates
What the tool creates in the way of certificates, why your browser keeps complaining, and when it is right to.
Reaching a changing address
Your line has no fixed address. How to reach it anyway, and when you cannot.
ZeroTier and Back To Home
Two services that dial out from the inside, and why WireGuard is usually still the answer.
Measuring
How to measure what you think you are measuring, and why the number is always lower than you hoped.
Cables and power
The layer where it actually goes wrong: copper, plugs and power over the same cable.
Checking Wi-Fi afterwards
What you measure once the access points are up, and how it compares with what you drew.
Planning first
Planning your addresses
Choose your address ranges before you fill anything in, because this is the hardest decision to reverse.
Planning your VLANs
Which networks earn a VLAN of their own, how to number them, and how that plan lands in the tool.
Choosing names
Names that still make sense a year later, for devices, ports and SSIDs.
Documenting and handing over
What belongs in the customer folder, and what the next person needs to pick your work up.
What the checks mean
Checks about cabling
The messages about cables, ports and roles, and what each one is telling you.
Checks about VLANs
The messages about VLANs, tags and the management VLAN, and what to do about each one.
Checks about addresses
The messages about addresses, subnets, DHCP and DNS, and what each one is telling you.
Checks about Wi-Fi
The messages about SSIDs, VLANs, CAPsMAN and repeaters, and what each one is telling you.
Checks about security
The messages about the firewall, management access, passwords and tunnels.
Checks about speed
The messages about MTU, offload, queues and throughput, and what each one costs you.
Search by what you see
No internet after applying
You pasted the script and nothing gets out any more. This is the order to look in.
One VLAN without internet
The rest of the network is fine, but one VLAN does not get out. Nearly always a tick box or a missing tag.
Websites stall while loading
Small things work, large things do not. That is not an outage, that is packet size.
Names do not resolve
Pinging 1.1.1.1 works, pinging a name does not. Then the network is fine and DNS is not.
You cannot reach the router any more
The script is pasted and nothing answers any more. There are four ways back, in this order.
A switch or access point disappeared
The second device in the site stopped answering. Usually it does not carry the management VLAN.
An address from the wrong range
The device does get an address, only not yours. Or it gets none and invents one.
Behind two routers
Browsing works, but port forwards, VPN and game consoles act strangely. There is probably another router in front of you.
A port forward that does not work
The dst-nat rule is in the script and still nothing arrives. Test from outside, then work down the list.
The VPN connects but nothing passes
The tunnel is up, one counter climbs, and you get nowhere. That is nearly always routing.
WireGuard never completes a handshake
No handshake ever arrives. WireGuard says nothing, so you have to work from the outside in yourself.
A site to site tunnel works one way
The tunnel is up, but only works if you start from the right side. Something is missing at one end.
Wi-Fi keeps dropping
Wi-Fi drops every few minutes, wired never notices: where to look, in order.
Wi-Fi is slow, the line is not
The meter says 25 Mbit on the phone and 900 on a laptop with a cable: where that gap comes from.
The phone sticks to the far access point
Sticky clients: why a phone will not move over, and what is actually yours to control.
Wi-Fi is gone after upgrading to v7
The Wireless menu is empty or renamed while bridges and DHCP are fine: this is the package problem.
The printer is not found
Printing worked, and then you introduced VLANs: why discovery stops at a network boundary.
Chromecast or AirPlay is not found
The cast button disappears the moment the phone and the TV stop sharing one network.
Cameras or the NVR lose their stream
Black gaps in the recording and cameras going offline: four causes, in order.
Provider TV stutters
Blocks in the picture, or a network that floods the moment the TV comes on.
Everything is slow at peak hours
Fast by day, sticky in the evening: measure before you turn any knobs.
The network is dead, every light is flashing
Every light blinking in the same rhythm and nothing responding: that is a loop.
The script errors partway through
The first lines go through and then an error appears: what each kind of message is telling you.
The router CPU sits at 100 percent
A processor that is full is usually not a fault but a choice you made earlier.
A wired port does not reach its speed
The port does gigabit, the meter says 94 Mbit: how to find where the speed goes.
A device on a PoE port does not come up
You hang an access point or a camera on a PoE port and nothing happens. This is the order to look in.
An SFP module has no link
The module is seated and the light stays off. What to read out before you touch any setting.
IPv4 works, IPv6 does not
Everything works, but the IPv6 test gives you nought out of ten. Where the chain breaks and how to see it.
The PPPoE client will not connect
The PPPoE client sits at dialing and never reaches connected. What to look at then.
The LTE or 5G modem gets no connection
The SIM is in, the antennas are on, and there is no connection. What to read out, and in what order.
A website breaks after switching on DNS filtering
You turn the adlist on and a checkout, a map or a login button stops working. This is how you find the blocked name.
The hotspot login page does not appear
The guest is on the network and the login screen never shows. Where the redirect gets lost.
An access point does not join CAPsMAN
The CAP script is pasted and the access point never finds the controller. Where it nearly always gets stuck.
The VPN connects but the LAN stays unreachable
The tunnel is up and you can reach nothing at the office. This is where the traffic stops.
A port forward works from outside but not from inside
It works from outside and not from inside. The traffic has to enter the router and leave again on the same side.
The clock on the router is wrong
Time looks like a detail until a certificate bounces off it and your log proves nothing.
A certificate warning on the router or the VPN
Read which warning it is first: unknown issuer, wrong name and expired are three different problems.
A backup will not restore
A .backup is an imprint of this one device. Moving to another model is a job for an export, not for a backup.
No space for an upgrade or a package
A small board has 16 MB of flash. One package, some log files and two backups later, that is gone.
The container does not run
Containers on RouterOS need a physical confirmation, and the generated script does not start them for you.
The speed limit has no effect
A queue that does nothing usually sees no packets at all. Look at the counter first, not at the limit.
OSPF neighbours stay in Init or Exstart
The neighbour state tells you where to look: Init is the hello, Exstart is the MTU.
A BGP session will not come up, or keeps flapping
BGP is TCP. Without a session, look at reachability and the firewall first and at BGP second.
The device is only reachable over MAC-WinBox
MAC-WinBox works and the IP address does not. That is not a fault, that is a precise clue.
When something goes wrong
Something unclear, or missing here? Tell us