Manual

Configurator manual

How to get from an empty screen to a working configuration, chapter by chapter.

Getting started

How a network works

Setting it up

Drawing

Bringing an existing configuration

After generating

Worked examples

Several devices and locations

Two offices, one design Two offices with the same VLAN numbers, an address range of their own, and a tunnel in between. A head office with five branches One head office, five branches that only talk to the hub, and numbering you can still read a year later. Switches in a ring: RSTP A ring of switches gives you a spare path, as long as RSTP knows which switch is in charge. Two routers as one gateway (VRRP) A second router that takes over the gateway address, and an honest list of what does not move with it. One CAPsMAN for several buildings One controller for the wifi of several buildings: when that is sensible and when you install two. Stretching layer 2 or routing One subnet across two locations, or two subnets with a route between them. The difference is bigger than it looks. A numbering plan that survives growth Numbering you can still read in three years and ten locations without opening a spreadsheet. Replacing a live network, device by device From old to new in steps you can undo one at a time. Rolling out twenty branches Design one branch properly and repeat it nineteen times, without collecting nineteen deviations. OSPF between locations Once there is more than one way to a site, something has to choose. That is the moment for OSPF. Three sites in a mesh Three tunnels instead of two, and the question of whether that extra path earns its upkeep. Two providers at every site A second line per branch is quick to draw; the question is what exactly takes over, and when. The same guest network everywhere One guest network, ten branches, and the question of where that traffic leaves the building. Telephones across locations One VLAN for the handsets, and the sober limits of priority on a line you share with everyone else. Cameras at several locations Cameras are cheap, bandwidth over a tunnel is not. Do the arithmetic first, build afterwards. A management network across locations The same VLAN number everywhere, a range of its own per location, and a way in that keeps working when the rest does not. Two cables between two switches Two cables side by side rarely give twice the speed, and they do cost a piece of handwork. Several buildings with fibre between them Four buildings, fibre between them, and one question that decides everything: do you route per building or not. Two tunnels between the same locations Building two tunnels takes a minute. Deciding which one is the spare is not done for you. Documenting a network of several locations The question is not whether you understand it, but whether your successor understands it in a year without calling you.

Every part in detail

System and time Name, password, clock, logging and updates: the lines every script needs. Management access Which services are open, from where, and how not to lock yourself out. Bridge and ports Which ports form one network, and what else you set on them. Bonding and LACP Several cables acting as one interface, for throughput or for redundancy. PoE-out per port Power over the network cable, set per port. WAN: the connection to the internet How your router gets online, and which fields on that page actually matter. Several uplinks: failover and load balancing Adding a second line, and choosing between taking over and sharing the load. Provider presets Picking your provider fills in the first uplink. What is and is not included. LAN and DHCP Your router's own address, and what it hands out to your devices. VLANs Several separated networks over the same cables, and which port carries what. Setting up Wi-Fi SSIDs, security, bands and VLANs, and why your device runs one Wi-Fi package rather than the other. Channels, width and power Bands, channel width, transmit power and DFS, and why wider is not always faster. CAPsMAN One place holding SSIDs, passphrases and VLANs, and access points that fetch their settings from it. Firewall and NAT The default rules, why they sit in that order, and what you add to them. Opening a port Reaching a device inside from the outside, and when you had better not. DNS The router as resolver for your network, and who sits above it. IPv6 A prefix from your ISP, a /64 per network, and a firewall that really has to be there. WireGuard Encrypted tunnels with keys your browser generates and a ready-made client configuration. VPN for individual users Getting in with the built-in VPN client of a phone or laptop, without installing an app. Tunnels between locations GRE, IPIP, EoIP and VXLAN: two networks joined, routed or as the same layer 2 network. QoS and bandwidth Queues that decide who waits when the line is full, and what they cannot fix. Static routes and policy routing A route to a network that does not sit behind your default gateway, and traffic that needs another exit. OSPF Routers telling each other which networks they have, instead of a list of static routes you maintain. BGP A session with your transit or another party, set up to the point where filters become hand work. The hotspot: a login page for visitors Visitors only get internet after they log in, with their own account and their own limit. The PPPoE server and RADIUS Your router as the provider: every customer logs in with their own account and gets their own address. VRRP: two routers, one gateway address When one router fails the other takes over the same gateway address, with nothing to change on your clients. Netwatch and monitoring Watch an address and act when it goes down, without a monitoring system being involved. Containers on RouterOS A small application alongside RouterOS on the same device, if your hardware can carry it. Services and tools Everything a router can do besides routing, and which of it belongs in a base configuration. MTU and jumbo frames The largest packets that fit through, and what happens when they just do not.

Recipes

Recipe: reaching a camera or doorbell from outside See the footage from your phone, without hanging the camera on the internet. Recipe: a NAS reachable at home and nowhere else Your files from the sofa, nothing from the internet. Recipe: IoT devices in a network of their own Give smart devices their own corner, without breaking casting and discovery by accident. Recipe: a printer usable from several VLANs Print from the office, the laptop and the phone, without giving up the separation. Recipe: reaching home or the office from the road From your phone or laptop into your own network, with WireGuard and a client configuration from the tool. Recipe: LTE as a backup line When the fixed line drops, the SIM takes over, and you knew beforehand that it would. Recipe: fixed public IP addresses A block of fixed addresses on the WAN, and a server that gets one of them. Recipe: keep phone calls clear when the line is busy A VLAN of its own for the phones and a queue that gives voice priority. Recipe: putting limits on the guest network Visitors get internet, but not your whole line and not your network. Recipe: guest Wi-Fi with a login page A captive portal for guests, on its own VLAN, away from the office network. Recipe: Wi-Fi in a warehouse or large building Coverage in a large building: draw first, drill second, measure third. Recipe: Wi-Fi that keeps working as you walk One SSID through the whole building, and a phone that follows you without dropping the call. Recipe: a camera network Cameras on their own VLAN, an NVR that may reach them, and nobody else. Recipe: television from your ISP (IPTV) Television over multicast: the IGMP proxy on the WAN and IGMP snooping on the bridge. Recipe: a server reachable from the internet Reachable from outside and nowhere else: a server in its own segment. Recipe: a backup routine you actually keep up Four files per site, one habit before every change, and a test you genuinely run. Recipe: a school or association building Three networks, coverage in every classroom, and a setup that makes sense without you. Recipe: Wi-Fi for a campsite or holiday park Many access points, a login page, and a fair share of a line that is never big enough. Recipe: AdGuard Home or Pi-hole in a container A DNS filter next to RouterOS on the same device, with an honest answer about when that is a good idea. Recipe: knowing before your customer calls Four things on the router itself, and an honest line where a monitoring system takes over.

Per model

hAP ax³ Five ports, 2.5 Gbit on the WAN side and Wi-Fi from the new wifi package. hAP ax² Five gigabit ports and Wi-Fi from the new wifi package, in the smaller case. hAP ac² The workhorse with two Wi-Fi packages on v7 and two traps worth knowing first. hEX (RB750Gr3) Five gigabit ports, no radios: the small wired router. hEX S (RB760iGS) The hEX with an SFP port and PoE-out: small, wired, a little more of it. RB5009 Eight gigabit ports, a 2.5 Gbit WAN and a 10 Gbit SFP+ cage in a metal case. L009 (L009UiGS-RM) Eight gigabit ports, a 2.5 Gbit SFP and PoE-out, in a rack-mount case. RB4011 (RB4011iGS+RM) Ten gigabit ports and a 10 Gbit SFP+ cage: the router for when you run out of sockets. CCR2004-16G-2S+ Sixteen gigabit ports, two 10-gigabit SFP+ cages and memory enough for a full routing table. CRS326-24G-2S+RM Twenty-four gigabit ports and two 10-gigabit SFP+ cages, as a RouterOS switch at the bottom of your rack. CRS328-24P-4S+RM Twenty-four gigabit ports with PoE-out and four 10-gigabit SFP+ cages, running RouterOS. cAP ax Ceiling access point with two radios, PoE-in on one port and PoE-out on the other. wAP ax Access point with two radios and one gigabit port, powered over that same cable. Chateau 5G ax R17 Router with a 5G modem, five ports including one at 2.5 Gbit, and dual-band Wi-Fi. CHR (Cloud Hosted Router) RouterOS as a virtual machine: you decide how many interfaces it has, the licence decides how fast they may go. hAP lite (RB941-2nD-TC) The smallest board in the catalogue: four 100 Mbit ports, one radio, 32 MB of memory. hEX lite (RB750r3) Five 100 Mbit ports, no radios: the smallest wired router. cAP lite (RBcAPL-2nD) A small ceiling access point: one port with PoE-in, one radio on 2.4 GHz. LtAP LTE6 kit A router with an LTE modem and one gigabit port: internet where there is no cable. Audience Three radios and two gigabit ports in a standing box for the living room. OmniTIK 5 PoE ac Five gigabit ports, four of which can feed power, plus one 5 GHz radio. FiberBox Plus (CRS305-1G-4S+OUT) Four 10 Gbit SFP+ ports and one gigabit copper port: a small fibre switch. CSS610-8G-2S+IN Eight gigabit ports and two SFP+ ports, running SwOS: a setup sheet instead of a script. hAP (RB951Ui-2nD) Five 100 Mbit ports, a single 2.4 GHz radio and a small board: the plainest complete hAP. hAP ac (RB962UiGS-5HacT2HnT) Five gigabit ports, an SFP cage and two radios: the big hAP of the previous generation. hAP ac lite (RB952Ui-5ac2nD) Dual-band Wi-Fi on a small board with 100 Mbit ports: the cheapest complete MikroTik. hAP mini (RB931-2nD) Three ports, one radio and 32 MB of memory: the smallest device the configurator knows. hEX PoE (RB960PGS) Five gigabit ports of which four supply power, plus an SFP cage: the wired router that feeds your cameras. hEX refresh (E50UG) The same five gigabit ports as the old hEX, but on ARM with 512 MB of memory and licence level 4. hEX S 2025 (E60iUGS) A 2.5 Gbit WAN port, four gigabit ports and a 10 Gbit SFP+ cage in the familiar small box. L009 with Wi-Fi (L009UiGS-2HaxD-IN) Eight gigabit ports, a 2.5 Gbit SFP cage and a 2.4 GHz radio running the new Wi-Fi package. RB5009UPr+S+IN (PoE) Seven gigabit ports that all supply power, a 2.5 Gbit WAN and an SFP+ cage: the PoE version of the RB5009. RB1100AHx4 (RB1100x4) Thirteen gigabit ports in a 1U chassis: the rack router without fibre and without Wi-Fi. CCR2116-12G-4S+ Thirteen gigabit ports, four SFP+ cages and 16 GB of memory: a Cloud Core Router for the rack. CCR2216-1G-12XS-2XQ Twelve times 25 Gbit and twice 100 Gbit: the largest router the configurator knows. CRS309-1G-8S+IN Eight 10 Gbit SFP+ cages in a small box: the fibre switch for a server cabinet. CRS317-1G-16S+RM Sixteen 10 Gbit SFP+ cages in 1U: the fibre switch for a rack full of servers. CRS354-48G-4S+2Q+RM Forty-nine gigabit ports plus SFP+ and QSFP+: the big access switch for a floor. CRS310-8G+2S+IN Eight 2.5 Gbit copper ports and two SFP+ cages: the small switch for fast desks. BaseBox 5 (RB912UAG-5HPnD-OUT) An outdoor box with one port and one 5 GHz radio: built for a link, not for an office. ATL 5G R16 (ATLGM&RG520F-EU) A small outdoor box with a 5G modem and one port: the device is the internet connection, not the network. CCR2004-16G-2S+PC Sixteen gigabit ports and two 10 Gbit cages, with no fan: a quiet edge router. CCR2004-1G-12S+2XS Twelve 10 Gbit and two 25 Gbit fibre cages, with one copper port beside them. KNOT IoT Gateway (RB924i-2nD-BT5&BG77) A small gateway with a modem, a radio and two 100 Mbit ports: built for sensors, not for an office. LtAP mini LTE kit (2024) A small LTE router with one port and one radio: internet for a place with no cable. mANTBox 2 12s (RB911G-2HPnD-12S) A sector antenna with the radio built in: the broadcasting end of a wireless network over distance. PowerBox (RB750P-PBr2) An outdoor router with four feeding ports: power and data to four devices at once. PowerBox Pro (RB960PGS-PB) Five gigabit ports, four of them feeding, plus an SFP cage: the larger PowerBox. RB450Gx4 Five gigabit ports and 1 GB of memory on a bare board: a solid small router. RB850Gx2 Five gigabit ports on an older board with a PPC processor: check which RouterOS is on it first. RB5009UPr+S+OUT Seven PoE ports, a 2.5 Gbit inlet and 10 Gbit fibre, in an outdoor enclosure. RDS2216 (ROSE Data server) Twelve fast ports up to 100 Gbit and 32 GB of memory: the heaviest device in our catalogue. CRS106-1C-5S Five 1 Gbit SFP cages and one combo port: a small fibre switch. CRS112-8P-4S-IN Eight feeding gigabit ports and four SFP cages: a small PoE switch. CRS304-4XG-IN Four 10 Gbit copper ports in a small box, with a gigabit port for management. CRS305-1G-4S+IN Four 10 Gbit SFP+ cages in a small box, with one gigabit port beside them. CRS312-4C+8XG-RM Twelve 10 Gbit ports in a rack unit, on a board with only 64 MB of memory. CRS320-8P-8B-4S+RM Sixteen 2.5 Gbit ports with PoE and four 10 Gbit cages, in a rack unit. CRS328-4C-20S-4S+RM Twenty SFP cages plus four 10 Gbit cages: the fibre switch for a rack.

Per provider

Coming from something else

RouterOS itself

Running it afterwards

Planning first

What the checks mean

Search by what you see

No internet after applying You pasted the script and nothing gets out any more. This is the order to look in. One VLAN without internet The rest of the network is fine, but one VLAN does not get out. Nearly always a tick box or a missing tag. Websites stall while loading Small things work, large things do not. That is not an outage, that is packet size. Names do not resolve Pinging 1.1.1.1 works, pinging a name does not. Then the network is fine and DNS is not. You cannot reach the router any more The script is pasted and nothing answers any more. There are four ways back, in this order. A switch or access point disappeared The second device in the site stopped answering. Usually it does not carry the management VLAN. An address from the wrong range The device does get an address, only not yours. Or it gets none and invents one. Behind two routers Browsing works, but port forwards, VPN and game consoles act strangely. There is probably another router in front of you. A port forward that does not work The dst-nat rule is in the script and still nothing arrives. Test from outside, then work down the list. The VPN connects but nothing passes The tunnel is up, one counter climbs, and you get nowhere. That is nearly always routing. WireGuard never completes a handshake No handshake ever arrives. WireGuard says nothing, so you have to work from the outside in yourself. A site to site tunnel works one way The tunnel is up, but only works if you start from the right side. Something is missing at one end. Wi-Fi keeps dropping Wi-Fi drops every few minutes, wired never notices: where to look, in order. Wi-Fi is slow, the line is not The meter says 25 Mbit on the phone and 900 on a laptop with a cable: where that gap comes from. The phone sticks to the far access point Sticky clients: why a phone will not move over, and what is actually yours to control. Wi-Fi is gone after upgrading to v7 The Wireless menu is empty or renamed while bridges and DHCP are fine: this is the package problem. The printer is not found Printing worked, and then you introduced VLANs: why discovery stops at a network boundary. Chromecast or AirPlay is not found The cast button disappears the moment the phone and the TV stop sharing one network. Cameras or the NVR lose their stream Black gaps in the recording and cameras going offline: four causes, in order. Provider TV stutters Blocks in the picture, or a network that floods the moment the TV comes on. Everything is slow at peak hours Fast by day, sticky in the evening: measure before you turn any knobs. The network is dead, every light is flashing Every light blinking in the same rhythm and nothing responding: that is a loop. The script errors partway through The first lines go through and then an error appears: what each kind of message is telling you. The router CPU sits at 100 percent A processor that is full is usually not a fault but a choice you made earlier. A wired port does not reach its speed The port does gigabit, the meter says 94 Mbit: how to find where the speed goes. A device on a PoE port does not come up You hang an access point or a camera on a PoE port and nothing happens. This is the order to look in. An SFP module has no link The module is seated and the light stays off. What to read out before you touch any setting. IPv4 works, IPv6 does not Everything works, but the IPv6 test gives you nought out of ten. Where the chain breaks and how to see it. The PPPoE client will not connect The PPPoE client sits at dialing and never reaches connected. What to look at then. The LTE or 5G modem gets no connection The SIM is in, the antennas are on, and there is no connection. What to read out, and in what order. A website breaks after switching on DNS filtering You turn the adlist on and a checkout, a map or a login button stops working. This is how you find the blocked name. The hotspot login page does not appear The guest is on the network and the login screen never shows. Where the redirect gets lost. An access point does not join CAPsMAN The CAP script is pasted and the access point never finds the controller. Where it nearly always gets stuck. The VPN connects but the LAN stays unreachable The tunnel is up and you can reach nothing at the office. This is where the traffic stops. A port forward works from outside but not from inside It works from outside and not from inside. The traffic has to enter the router and leave again on the same side. The clock on the router is wrong Time looks like a detail until a certificate bounces off it and your log proves nothing. A certificate warning on the router or the VPN Read which warning it is first: unknown issuer, wrong name and expired are three different problems. A backup will not restore A .backup is an imprint of this one device. Moving to another model is a job for an export, not for a backup. No space for an upgrade or a package A small board has 16 MB of flash. One package, some log files and two backups later, that is gone. The container does not run Containers on RouterOS need a physical confirmation, and the generated script does not start them for you. The speed limit has no effect A queue that does nothing usually sees no packets at all. Look at the counter first, not at the limit. OSPF neighbours stay in Init or Exstart The neighbour state tells you where to look: Init is the hello, Exstart is the MTU. A BGP session will not come up, or keeps flapping BGP is TCP. Without a session, look at reachability and the firewall first and at BGP second. The device is only reachable over MAC-WinBox MAC-WinBox works and the IP address does not. That is not a fault, that is a precise clue.

When something goes wrong

Something unclear, or missing here? Tell us