Current config review
We go through the config export and flag duplicate or risky rules, exposed services and the RouterOS version.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
In many offices a MikroTik router is the only thing between staff and the internet, and it often runs a default config plus a few rules copied from a forum. During MikroTik setup we rewrite the firewall, NAT, DHCP and routing cleanly. Management access is locked down and RouterOS is moved to a current stable release.
MikroTik setup means configuring a MikroTik router as the office internet gateway, with a clean, documented firewall, NAT, DHCP and routing. It is aimed at offices whose router still runs a default config or rules copied from a forum, where the internet drops every few days, the password left with a former admin, or Winbox is reachable from the internet. PikoSystem backs up the current config first, rewrites filter and NAT rules, disables unused services such as Telnet and FTP, limits Winbox and SSH to allowed addresses, and sets up dual-WAN failover or PCC load balancing, plus WireGuard VPN and a guest hotspot where needed. Risky changes are applied in Safe Mode. You receive a final config export with each section explained, a firewall rule list with reasons, new admin accounts and a change report.
We go through the config export and flag duplicate or risky rules, exposed services and the RouterOS version.
Filter and NAT rules are rewritten in order. Unused services such as Telnet, FTP and API are disabled, and Winbox and SSH are limited to allowed addresses.
We keep a second link on standby with route distance and check-gateway, or balance traffic across links with PCC.
WireGuard, L2TP/IPsec or SSTP for remote staff and branch connections.
Guest traffic is isolated from the internal network, with a login page and speed limits where needed.
We schedule automatic config backups and send logs to a syslog server so events can be traced later.
Small models such as the hAP lite are built for homes and tiny offices, and a few firewall rules plus VPN and queues will max out their CPU. A typical office is better served by an RB5009 or hEX S, while the CCR series suits fast links and many branches. When comparing models, use MikroTik's published test results with firewall and IPsec enabled.
If you already run a virtualization host, MikroTik CHR can run as a VM on VMware or Proxmox. The free CHR tier limits each interface to 1 Mbps, so real use needs a P1 license or higher.
Many routers have no final drop rule in the input chain, which leaves DNS and Winbox reachable from the internet. With allow-remote-requests enabled and port 53 open on the WAN, the router ends up amplifying DNS attacks for someone else. Older RouterOS 6 builds also carry the well-known 2018 Winbox vulnerability that leaks credentials.
FastTrack combined with queues is another trap. Fasttracked connections skip mangle and simple queues, so speed limits silently stop working. Neighbor Discovery and MAC Server should not stay enabled on the WAN interface either.
A PCC classifier of both-addresses-and-ports spreads one user's connections across several public IPs, and banking sites and admin panels drop the session. A src-address classifier avoids most of that. Traffic arriving on each WAN also needs a connection mark so replies leave through the same link, or port forwards break.
check-gateway=ping only checks that the modem or gateway answers, so an outage further upstream goes unnoticed. For real failover, use recursive routes to an external address with scope and target-scope set, or Netwatch.
RouterOS 7 adds WireGuard, a rewritten routing engine for OSPF and BGP, and containers. Routing tables must now be created explicitly and the route routing-mark parameter became routing-table, though, so PCC and policy routing configs need a review before the upgrade.
The safe path is to move to the latest 6.x long-term release, take both a binary backup and a text export, then upgrade to 7. A binary backup is meant for the same device, while the export lets you rebuild on different hardware. Afterwards, upgrade the RouterBOARD firmware as a separate step and reboot.
We get temporary access and take a backup and export of the current config before touching anything.
We list the problems and proposed changes and go through them with you.
Changes go in at an agreed time. Risky changes are made in Safe Mode, so the router reverts if we lose the connection.
We test internet, VPN, failover and access rules, then hand over documentation and credentials.
Yes, if you have physical access to the device. It usually needs a reset and a fresh config, so we first go through the services and settings you rely on. If an old backup exists, the job is shorter.
Yes. We configure the MikroTik hotspot with a login page, time or data limits and per-user speed limits. For a large number of users, authentication can be moved to User Manager or a RADIUS server.
Yes, under a support contract. RouterOS updates, log reviews and config backups are done on a schedule, and response times are set in the agreement.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.