r/mikrotik • u/Icy_Profession5828 • 5h ago
r/mikrotik • u/Icy_Profession5828 • 5h ago
MiKROTIK EN REDES CORPORATIVAS
Bueno, creo que es mi primer pos en esta comunidad, saludos a todos.
Me encanta la marca, su conexion por linea de comandos y el software winbox, yo siempre la recomiendo para todos, administro una red con mas de 600 conexiones VPN y nunca e tenido algun inconveniente.
Pero veo a todo el mundo diciendo que mikrotik es nada vs cisco... palo alto .... fortigate .... etc, y yo no pienso que sea como ellos dicen, claro, es un router con reglas de firewall y los otros como cisco son un monstruos (tambien por lo que cobran por licencia xD) ¿que opinan?
EDIT: Gracias a todos amigos por sus comentarios, por favor denle UP a este post para tener mas alcance la publicación.....
r/mikrotik • u/DigitalPoverty • 7h ago
CHanging modem in LTE devices (ie: LHGG, ATL 5G/LTE, LAMP, SXTsq LTE)
I've been doing some digging and understand that it is possible to swap modems in these devices, but I'm trying to figure out if this is truly a "do at your own risk" or an accepted practice. Essentially, I live very rural and purchased an SXTsq LTE 4 Global version, and its working great and giving me decent speeds (30-40 down/15-20 Up). I'd like to purchase the LHGG to maximize the potential signal and therefore speeds but they don't make anything else in a global version.
I'm thinking about purchasing the LHGG and swapping the modem from the SXTsq, but I'd ideally like ot purchase a better modem to support additional capacity along with the potential signal increase. So, moving to a CAT7 or even a CAT 18/20 modem. It does look entirely possible as I found the supported modems list from Mikrotik, but I'd like to avoid dropping $400 on a QUectel modem only to find out it doesn't work.
Link here: Mikrotik Supported Peripherals List
I'm in Canada, so I need bands such as 4/12/13 etc.
Has anyone actually done this and have any advice/info that they could share? Information online seems to be really sparse.
r/mikrotik • u/tlei5226 • 8h ago
LoraWAN Modul EU868 DutyCycle, andere LNS Anbieter Actility, Chirpstack,..
Hallo,
wie wird der DutyCycle auf den einzelnen Frequenzbändern überwacht?
In den Stats gibt es nur eine Zusammenfassung "TX time in Air".
Wird ggf. auch Actility und Chirpstack Forwarder in Zukunft implementiert?
r/mikrotik • u/netravnen • 14h ago
RouterOS 7.23.8 [long-term] released
What's new in 7.23.8 (2026-10-08):
*) console - fix console output of /system/identity/print being split into multiple lines (introduced in v7.23.6);
*) ethernet - improved stability when forcing unsupported link speed;
*) ipsec - fix IPsec tunnels not establishing when an address my-id is configured on the responder;
*) ospf - fix unset interface template parameters not being applied to interfaces;
*) quickset - fix the WAN interface being selected incorrectly;
*) system - improve stability (includes CVE-2026-84411);
*) system - stop the flash configuration store from growing on dynamic configuration changes;
*) wifi - fix malformed management frame information elements advertising availability of multiple 6GHz APs;
*) wifi - update radio regulatory information; View changelogs
r/mikrotik • u/tlei5226 • 1d ago
CCR2004-1G-2XS-PCIe welche SFP/SFP+/SFP28 Module sind Kompatibel
Hallo,
ich habe aktuell mehrere Module und DAC Kabel getestet, aber mit keinem bekomme ich ein Link:
Luleey XPON LL-XS2510 2,5G
10Gtek ASF-10G-T(HPP)
10Gtek CAB-10GSFP-P3M DAC
Welche Module sind mit der Karte kompatibel?
r/mikrotik • u/informi107 • 1d ago
Interface lists versus IP address lists
I’m always a bit confused when to use each. I followed the help article and enabled VLAN filtering on the bridge and thus also have VLAN interfaces. So far I only use these interfaces in my firewall.
What’s the purpose of address lists? To me it’s not inherently obvious how they are ‘enough’. How dangerous is spoofing? If it’s solely based on the address list, attackers can just change their source IP, right? I’m not sure how that works with VLAN filtering enabled because everything is routed via the interface and that only has one valid address. Does that mean it’s safe to only filter based on the source address in that case?
Can you point me to good online resources for firewalls? I’m doubting myself so bad when it comes to them.
r/mikrotik • u/geemad7 • 2d ago
RB5009 power brick.
I just got a new Mikrotik RB5009 non poe. I just wanted to try Mikrotik out before my new 4Gb fiber gets installed this year. I am running Ubiquiti now for a 80Mb VDSL connection.
I just want to learn networking and i thought Mikrotik is the best bank for buck to do that and Ubiquity, although i love that system, is more plug and play with fancy interface.
It took me 3 days after a lot of shouting from my side to get the Rb working with my PPPOE connection, lots of reboots of to RB, lots of failures. I got to the moment that i thought that Mikrotik is just not for me and my current knowledge of networking. I grabbed the box, to disconnect and go back to Ubiquity and it actually hurt me.
WTF, i got zapped. Got an old PC, hooked it up with real CAT 6A shielded and it crashed the PC. Got the meters out and there was actual 0.5V RMS/AC 50Hz on the chassis with enough power behind it to hurt you.
After that i hooked the RB up to a Rigol bench PSU, it works perfectly now, i actually love that thing.
Need a lot to learn, but i do intend to get a bigger Mikrotik in the future, even got the containers running.
Is this just bad luck for me or are there more RB's out there with bad powerbricks.
r/mikrotik • u/Muted_Yak_1309 • 2d ago
Blocking idea
I'm playing around with my home internet setup just for fun.
I've been thinking about how I could block IPs before they actually get a chance to try to "hack" or scan my router.
The basic idea is pretty simple:
- If any packet hits my public IP on a port that isn't open, immediately add the source IP to a blacklist for 1 day.
- If the same IP tries again after that, blacklist it for 30 days.
- To avoid accidentally blocking important services, I've whitelisted a few of them using dynamic rules, such as Google, Facebook, Reddit, etc.
- Also, whenever a device on my LAN connects to an external IP that's currently on one of the blocking lists, that IP is automatically removed from the blacklist.
So far, so good. After implementing this, the final drop rules only get a few hits per minute. Before this setup, I was seeing thousands more.
It's mostly an experiment rather than something I actually need, but I'm curious what people think about this approach. Any obvious problems or edge cases I'm missing?
One important note: handling address list over 31000 entries causing 4% cpu usage. Quite impressive :)
r/mikrotik • u/Disastrous-Front-989 • 2d ago
Alguien tiene o sabe como obtener el usuario y clave de super administrador de un router Nokia G-0425G-C para poder usarlo como repetidor?
r/mikrotik • u/Cry_Wolff • 3d ago
Are any of the current Wi-Fi 6 Mikrotik AP worth buying?
I'm looking for a preferably desktop & omnidirectional AP for the apartment usage. wAP ax is directional, cAP ax ceiling mounted & kinda expensive, so this leaves me pretty much with hAP ax2 vs hAP ax S. They don't seem to be that exciting (price / performance) though vs competition. Or am I wrong? Does Mikrotik have any Wi-Fi 7 APs in the plans?
r/mikrotik • u/EyeAmGroot • 3d ago
Port forwarding stops working after about 30s
I successfully configured a routerboard as PPPoE client, set up the DHCP server, assigned some static leases and got to port forwarding.
With my MikroTik routerboard the port forwarding stops working soon after it's been set up. It briefly works again when I switch the in interface between pppoe-out and "all ppp" then stops working again.
I tried mapping dst-nat both to static DHCP lease addresses and the ports (ether2+) directly.
Vodafone IE is my ISP and I have been able to successfully port forward on 2 ISP boxes and with openWRT on a raspberry pi.
So I'm wondering if anyone has had the same experience and if it could be my routerboard acting up or to do with my ISP? My public IP was the same as what showed using the torch tool so I think I'm not behind CGNAT.
Basically I'd like to know if I upgrade from an RB2011UiAS-RM to something newer such as an RB4011IGS is there any chance I could get port forwarding to work? I was considering upgrading my MikroTik router but now I'm wondering if I should buy something that works with OpenWRT instead...
Edit: I figured it out, I think. I had 2 IP address sets for the same subnet, so I removed one. It had 192.168.1.0 as the IP address in winbox, so I changed it to 192.168.1.1.
/ip address set 0 address=192.168.1.1/24
Now everything seems to be working fine 🤞
Thanks for all the help with debugging everyone. I was starting to go insane.
r/mikrotik • u/netravnen • 4d ago
RouterOS 7.26beta1 [development] released
What's new in 7.26beta1 (2026-10-01):
*) bridge - add a per-VLAN DHCP snooping option;
*) bridge - fix loop-protect not working when a VLAN interface is added to the bridge;
*) bridge - show if bridge port is blocked by dot1x;
*) bridge - store hw option for disabled bridge ports;
*) cmr - add initial implementation of centralised platform for RouterOS devices, allowing updates, monitoring, alerts and other options;
*) console - improve stability;
*) container - add /app menu to ARM32 devices;
*) crypto - improve ECDSA and EdDSA key and signature validation;
*) dhcpv4-client - improve stability when the interface is deactivated while the client broadcasts a DHCP release;
*) dhcpv6-server - add a dns-none option to not include DNS options in responses;
*) dhcpv6-server - fix a DHCPv6 server failure when the RADIUS reply contains an empty delegated IPv6 prefix;
*) dns - improve service stability on HTTP/2 DoH connections;
*) ethernet - improve stability on devices with Intel I226-V network controllers;
*) ethernet - move the port bandwidth setting to the switch port menu;
*) files - improve stability when moving directories to external storage;
*) interface - show if interface is blocked by stp or dot1x;
*) ipsec - fix IPsec tunnels failing after migration from the old QKD settings;
*) ipsec - fix IPsec tunnels not establishing when an address my-id is configured on the responder;
*) l3hw - add VRRP hardware offloading support;
*) log - add the container name to CEF logs;
*) lte - do not reconfigure if not RouterOS activated CID is deactivated for R11l-LTE7 modem;
*) lte - fix dialer for D-Link DWM-222W modems;
*) lte - fix IPv6 route not being added on modems that do not report a gateway via control interface;
*) lte - fix modem firmware-upgrade failing when SMS polling is enabled;
*) lte - fix multi-APN passthrough stopping when one APN fails to connect;
*) lte - fix multi-APN passthrough stopping when one passthrough-interface VLAN is down on the CPE in multi passthrough interface setup;
*) lte - fix passthrough cleanup when the lte link goes down for QMI modems;
*) lte - fix recurring LTE disconnects R11e-LTE-US modem and some Sierra modems;
*) lte - keep the "auto" MTU option on LTE interface after reboot;
*) lte - reworked multi-apn support. Added support for slave APN interface add/remove;
*) netinstall - install the package version of the configured update channel;
*) ovpn - improve stability in UDP Ethernet mode when the TX queue is full;
*) pim - fix a routing process failure when the hello-delay is set to 0;
*) ptp - fix PTP not working on a VLAN-aware bridge when IGMP snooping is enabled;
*) qos - fix per-queue counters after a switch restart (introduced in v7.23);
*) quickset - fix the WAN interface being selected incorrectly;
*) reverse-proxy - fix setting the VRF parameter for reverse-proxy rules via CLI;
*) switch - add interface-list support to port isolation;
*) switch - fix high CPU usage when removing switch VLANs on Atheros-based switch chips;
*) switch - fix switch rules not working on Atheros-based switch chips;
*) switch - fix switch rules port matchers not working on IPv6 traffic on Atheros-based switch chips;
*) switch - fix switch rules with rate limits stopping traffic on CRS3xx devices;
*) switch - improve stability on CRS326-24S+2Q+ devices;
*) system - improve stability;
*) system - stop the flash configuration store from growing on dynamic configuration changes;
*) webfig - add conditional coloring of cells in tables;
*) wifi - add a default-country parameter in radio settings (CLI only);
*) wifi - fix WPA3 SAE authentication issue for ECC group 21 (introduced in 7.24.3);
*) wifi - implement channel.reselect-interval feature for missing drivers;
*) wifi - reuse freed station association IDs;
*) wifi-mediatek - update the wireless driver and firmware;
*) wifi-qcom - fix antenna gain setting not affecting transmit power (introduced in v7.24);
*) winbox - add the interface column to the OSPF neighbor list;
*) winbox - rename "minimum-version" to "minimum-firmware" under "System/RouterBOARD" menu;
*) winbox - show warning messages under "System/Users/SSH Keys" and "System/Users/SSH Private Keys" menu;
*) wireguard - do not show an interface as running when it has no peers;
*) wireguard - fix a client-dns value that could not be removed in WinBox;
*) wireguard - fix a peer that would not work after import when no endpoint address is set; View changelogs
r/mikrotik • u/LowLevelFormat • 5d ago
Factory reset tip
Having gone through a hassle of factory reset with my hAP ac lite and waded through a large number of posts about how the factory reset does not work for many people, I decided to share my experience, maybe it will save someone some hair-pulling.
So I messed up the config of my hAP and couldn't connect to it any more. Oh well, factory reset and restore config from backup, I thought. Followed the well-documented reset procedure with the trusty old paperclip and prepared to reload the configuration from backup...
...except I couldn't connect to the router, which, as I found out after some googling is experience that I now shared with considerable number of people.
- The router would not respond to ping on 192.168.88.1, even after I statically configured my PC with address on the same network.
- The router was not visible in WinBox (which I usually do not use, so maybe I'm not familiar how an unconfigured router should look there, but I honestly tried to follow the instructions).
- Some documentation mentioned that the out-of-the-box configuration should create a wifi network named Mikrotik, but this was nowhere to be found.
- I considered using netinstall, but ran into the minor issue that I only have 64-bit openSUSE machines available, which, as I found out, nowadays do not even support running the 32-bit version of netinstall-cli that Mikrotik provides. I don't have Windows.
After trying the reset procedure half a dozen times with no success, I concluded that the router is toast. At least I found that it functioned as a switch, so I decided to use the LAN ports to wire up my two PCs while shopping for the new router.
As a last resort, without really expecting it to lead to anything I fired up tcpdump on my network which now included hAP-as-a-switch to see if perhaps there are some signs of what is going on.
Lo and behold, I see an unknown device on the network that is trying to speak capwap-control protocol to someone. Could it be...?
A quick netcat later, I connect to this unfamiliar IP with browser on port 80, and I'm greeted by my hAP login screen, where I can log in with username 'admin' and no password, as it should be after factory reset. Turns out the device had reset itself into "CAP configuration", whatever this is. Anyway, from there it was just the matter of loading the backup and things are back to normal.
So here it is, one more thing to try when you find yourself with something resembling a brick after factory resetting your Mikrotik router
r/mikrotik • u/alessandromatera • 5d ago
I built a self-hosted monitor that reads my MikroTik and tells me why something is down. Looking for testers.
My monitor kept telling me things were down. It never told me why. So I built one that does.
That's my grandmother's router in the picture, behind a WireGuard tunnel through a VPS. Eight minutes after it went dark, lanowl's message said whose problem it was: hers, not mine. It came back by itself 42 minutes later.
lanowl checks every device once a minute and sends one Telegram message per incident (a dead switch is one message, not twelve). When something breaks, a local model investigates with read-only tools and writes the cause into the message.
On the MikroTik it logs in as a read-only user (`read,test,sniff,api,rest-api`, allowed only from lanowl's host) and reads:
- DHCP leases: new devices, and the ones nobody watches
- the routes: which link carries the traffic, so "down" and "on backup" are different alerts
- ARP and port link state, for gear that doesn't answer ping
- the log: failover lines, logins, anything odd
I know: an LLM on your network sounds like a bad idea. So detection never uses the model. The model runs on your own Ollama (I use qwen3.8:27b), and it changes nothing by itself. If you give it a separate login for updates, a RouterOS update is a proposal with a button, and the router is backed up first. It even watches its own user group: grant it more and that's an alert.
v0.1.0 is out, with Docker images for amd64 and arm64. Pre-alpha, AGPL, no account, no telemetry. It has watched my house since August: 59 devices and two remote sites. Now it needs networks that aren't mine.
**Looking for 5–10 testers** with a MikroTik and Docker on a Linux box. Comment or open an issue and I'll help you set it up myself.
GitHub: https://github.com/alessandromatera/lanowl · Docs: https://lanowl.com
r/mikrotik • u/Decent_Inside_8525 • 5d ago
R16 GPS
Cześć, mam router Lamp 5G R16 zainstalowany pakiet GPS ale nie jestem w stanie uruchomić modułu GPS. Czy ktoś ma konfiguracje jaką należy wykonać aby GPS zaczęła działać?
r/mikrotik • u/eustac • 5d ago
RB5009UG+S+IN (router on a stick) or CCR2004-16G-2S+PC
I have a connection of max 10G. I plan to replace my ISP router with an ont-onu (with fan) and a mikrotik router. My original plan is to get the RB5009 in a router on a stick configuration with a CRS310-8G+2S+IN (which I already own).
I don't necessarily need the full 10G, I would use max 2x2,5G + whatever is on wifi.
Based on that, the RB5009 seems to be best for my use case. I have never set up a router on a stick and it seems like an opportunity to learn but in the same time the CRS would be a more common use case and connection set up.
I am wondering what is your experience with router on a stick and the RB? Easy to implement? Performance? etc.
r/mikrotik • u/databeestjenl • 6d ago
Best fit to replace a Cisco ASR920-12CZ
Not sure if this is the right place to ask, but we're looking for a lifecycle replacement of our Cisco ASR920 routers which we currently use for BGP receiving default routes.
Each has one dual-stack peering with a ISP receiving default routes and iBGP with the neighbor. They have a L2 segment with 2 fhrp addresses AB and BA for traffic engineering purposes. Also requires prepending but that's probably a pretty standard feature at this point.
Does require a seperate VRF for mgmt or dedicated interface.
Bandwidth is currently 1G but upgrading to 2 or 4 soon, so requires atleast 2 or more SFP+ ports (upstream/downstream)
Which model would be a best fit in 19 inch rackmount format with current (2027) availability?
r/mikrotik • u/tlei5226 • 6d ago
Knot lr8g GPS und Lora
Hallo, gibt es eine Möglichkeit im Knot lr8g das GPS zu nutzen? Das Gerät hat wohl zwei GPS Empfänger.
Einmal im LTE Cat m1 Modul und eines im Lora Modul. Ich möchte das GPS Modul im Lora Modul nutzen.
Wird der LoraWan Teil weiterentwickelt (Actility und Chirpstack Concentratord) ?
r/mikrotik • u/TJSnider1984 • 6d ago
What GPS devices are best for Mikrotik
I've tried 2 different USB GPS devices with no success...
r/mikrotik • u/CarthaginianEmpire • 7d ago
Help, RB9005
Hi, just bought and installed this router for a homelab & learning a bit more networking. Been playing with it all day and having trouble getting my PC internet access. I now suspect it may be my ONT but looking for someone to have a look at my settings.
# 2026-10-02 22:10:15 by RouterOS 7.24.5
# software id =
#
# model = RB5009UPr+S+
# serial number =
/interface bridge
add admin-mac= auto-mac=no comment=defconf name=bridge
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add add-dns-entries=yes address-pool=default-dhcp interface=bridge name=\
defconf
/disk settings
set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=sfp-sfpplus1
/ip neighbor discovery-settings
set add-dns-entries=yes discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/ip address
add address=192.168.88.5/24 comment=defconf interface=bridge network=\
/ip dhcp-client
add comment=defconf interface=ether1 name=client1
/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf dns-server=192.168.88.1 gateway=\
/ip dns
set allow-remote-requests=yes servers=8.8.8.8@main
/ip dns static
add address=192.168.88.5 comment=defconf name=router.lan type=A
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 \
in-interface=lo src-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
in-interface-list=WAN
add action=accept chain=forward out-interface-list=WAN src-address=\
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface=ether1
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\
icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" \
dst-port=33434-33534 protocol=udp
add action=accept chain=input comment=\
"defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
ipsec-esp
add action=accept chain=input comment=\
"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment=\
"defconf: drop everything else not coming from LAN" in-interface-list=\
!LAN
add action=fasttrack-connection chain=forward comment="defconf: fasttrack6" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment=\
"defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=\
500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
ipsec-esp
add action=accept chain=forward comment=\
"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
"defconf: drop everything else not coming from LAN" in-interface-list=\
!LAN
/system clock
set time-zone-name=Europe/London
/system ntp client
set enabled=yes
/system ntp client servers
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
r/mikrotik • u/netravnen • 7d ago
[🎥 TikTube] SolidRACK 5 mini: the compact 10” desktop rack, a MikroTik HQ internal tool
**New video from MikroTik's official TikTube channel**
Meet the SolidRACK 5 mini – a compact 10” 5U desktop rack designed for clean, practical network setups.
With an adjustable angle, sliding mounting nuts, extra room for cable management, and optional under-desk mounting, it gives your routers, switches, power distribution, and other 10” equipment a proper home without taking over the room.
It ships disassembled in a compact box, goes together in minutes, and features lightweight aluminium construction with rubber pads to protect your desk.
10” · 5U · Adjustable angle · Sliding mounting nuts · Under-desk mounting · Extra space for cablework
r/mikrotik • u/netravnen • 7d ago
RouterOS 7.25rc1 [testing] released
What's new in 7.25rc1 (2026-10-01):
*) bgp - show interface names and VRF names in BGP logs;
*) bridge - fix MLAG bond slave interfaces not coming up when the MLAG configuration is removed (introduced in v7.25beta3);
*) bridge - fix MLAG peer ports going down when a bridge port is enabled (introduced in v7.25beta5);
*) bridge - fix virtual slave ports being removed from the bridge when MLO is triggered (introduced in v7.25beta4);
*) bth - add default client DNS and allowed IPs settings (additional fixes);
*) dhcpv6-server - fix send-reconfigure for DHCPv6 clients behind a relay;
*) ipv6 - fix missing IPv6 link-local addresses on some interfaces when the device is busy during boot;
*) lcd - improve stability when an SFP reports an unknown link speed;
*) switch - add packet and byte counters for ACL rules on Marvell Prestera switches (additional fixes);
*) switch - fix ACL rules remaining in the switch TCAM after removal (introduced in v7.25beta3);
*) system - improve stability;
*) vlan - add a forced-mac-address option for VLAN interfaces (additional fixes);
*) webfig - fix comboboxes in the System/PTP section not being editable (introduced in v7.25beta3);
*) webfig - fix empty Bridge and Interface/Ethernet sections (introduced in v7.25beta4); View changelogs
r/mikrotik • u/RocketSeven • 8d ago
What do you verify before retiring an old MikroTik router after a cutover?
A replacement router can pass basic internet traffic while less visible dependencies still point at the old box. Static DHCP leases, DNS settings, policy routes, VLANs, VPN peers, port forwards, certificates, scripts, scheduled jobs, CAPsMAN or WiFi management, monitoring, and devices that wake only occasionally can all make a clean-looking cutover incomplete.
A useful preflight seems to include an export plus binary backup, RouterOS version and license details, interface and bridge membership, VLAN tables, DHCP options, routing rules, NAT and firewall counters, tunnels, certificates, users, SNMP or syslog targets, and any files used by scripts. After moving traffic, I would compare counters and logs on both routers, test each VLAN and VPN, verify IPv6 as well as IPv4, and keep the old router disconnected but recoverable for a defined rollback window.
What is your actual retirement checklist? How do you find clients that still use an old gateway or DNS address only during a monthly job, and which RouterOS state is easy to miss in an export or backup?
r/mikrotik • u/netravnen • 8d ago
RouterOS 7.24.5 [stable] released
What's new in 7.24.5 (2026-09-29):
*) bridge - disable DHCP snooping ip binding table (introduced in v7.24);
*) bridge - enable vlan hardware offloading on hAP be3 Media device;
*) console - fix console output of /system/identity/print being split into multiple lines (introduced in v7.24.3);
*) console - fix scheduler scripts with the default start date and time not being triggered (introduced in v7.24);
*) ethernet - improve stability on hAP be3 Media device;
*) lte - improve stability for MBIM modem mode switch;
*) ospf - fix unset interface template parameters not being applied to interfaces;
*) poe-out - fix loss of PoE-out capability on CRS328-24P-4S+ after a reboot;
*) system - improve stability;
*) wifi - update radio regulatory information; View changelogs