PikoSystem IT engineering services
Network & Virtualization

MikroTik Router Setup and Support

In many offices a MikroTik router is the only thing between staff and the internet, and it often runs a default config plus a few rules copied from a forum. During MikroTik setup we rewrite the firewall, NAT, DHCP and routing cleanly. Management access is locked down and RouterOS is moved to a current stable release.

Tools & technology mikrotik
  • MikroTik RouterOS
  • Winbox
  • MikroTik CHR
  • WireGuard
  • L2TP/IPsec
  • PCC
  • Hotspot
  • The Dude
  • Syslog
6work areas
4deliverables
4steps

What is MikroTik Setup?

MikroTik setup means configuring a MikroTik router as the office internet gateway, with a clean, documented firewall, NAT, DHCP and routing. It is aimed at offices whose router still runs a default config or rules copied from a forum, where the internet drops every few days, the password left with a former admin, or Winbox is reachable from the internet. PikoSystem backs up the current config first, rewrites filter and NAT rules, disables unused services such as Telnet and FTP, limits Winbox and SSH to allowed addresses, and sets up dual-WAN failover or PCC load balancing, plus WireGuard VPN and a guest hotspot where needed. Risky changes are applied in Safe Mode. You receive a final config export with each section explained, a firewall rule list with reasons, new admin accounts and a change report.

When you need MikroTik Setup

  • The office internet drops every few days and we reboot the router.
  • Whoever configured our MikroTik has left, and we don't have the password.
  • We pay for two internet links, but when one fails everything goes down.
  • Winbox is reachable from the internet and that worries us.

What MikroTik Setup includes

01

Current config review

We go through the config export and flag duplicate or risky rules, exposed services and the RouterOS version.

02

Firewall and router hardening

Filter and NAT rules are rewritten in order. Unused services such as Telnet, FTP and API are disabled, and Winbox and SSH are limited to allowed addresses.

03

Multi-WAN and failover

We keep a second link on standby with route distance and check-gateway, or balance traffic across links with PCC.

04

VPN and remote access

WireGuard, L2TP/IPsec or SSTP for remote staff and branch connections.

05

Hotspot and guest Wi-Fi

Guest traffic is isolated from the internal network, with a login page and speed limits where needed.

06

Backups and logging

We schedule automatic config backups and send logs to a syslog server so events can be traced later.

What you get from MikroTik Setup

  • Final config export with each section explained
  • Firewall rule list with the reason for each rule
  • New admin accounts, with the default admin account disabled
  • Change report against the previous config

MikroTik Setup: a practical guide

Which MikroTik router model fits an office?

Small models such as the hAP lite are built for homes and tiny offices, and a few firewall rules plus VPN and queues will max out their CPU. A typical office is better served by an RB5009 or hEX S, while the CCR series suits fast links and many branches. When comparing models, use MikroTik's published test results with firewall and IPsec enabled.

If you already run a virtualization host, MikroTik CHR can run as a VM on VMware or Proxmox. The free CHR tier limits each interface to 1 Mbps, so real use needs a P1 license or higher.

Common MikroTik configuration mistakes

Many routers have no final drop rule in the input chain, which leaves DNS and Winbox reachable from the internet. With allow-remote-requests enabled and port 53 open on the WAN, the router ends up amplifying DNS attacks for someone else. Older RouterOS 6 builds also carry the well-known 2018 Winbox vulnerability that leaks credentials.

FastTrack combined with queues is another trap. Fasttracked connections skip mangle and simple queues, so speed limits silently stop working. Neighbor Discovery and MAC Server should not stay enabled on the WAN interface either.

MikroTik load balancing: PCC details people miss

A PCC classifier of both-addresses-and-ports spreads one user's connections across several public IPs, and banking sites and admin panels drop the session. A src-address classifier avoids most of that. Traffic arriving on each WAN also needs a connection mark so replies leave through the same link, or port forwards break.

check-gateway=ping only checks that the modem or gateway answers, so an outage further upstream goes unnoticed. For real failover, use recursive routes to an external address with scope and target-scope set, or Netwatch.

Upgrading RouterOS 6 to 7: what changes

RouterOS 7 adds WireGuard, a rewritten routing engine for OSPF and BGP, and containers. Routing tables must now be created explicitly and the route routing-mark parameter became routing-table, though, so PCC and policy routing configs need a review before the upgrade.

The safe path is to move to the latest 6.x long-term release, take both a binary backup and a text export, then upgrade to 7. A binary backup is meant for the same device, while the export lets you rebuild on different hardware. Afterwards, upgrade the RouterBOARD firmware as a separate step and reboot.

How MikroTik Setup works

  1. 01

    Access and backup

    We get temporary access and take a backup and export of the current config before touching anything.

  2. 02

    Review and proposal

    We list the problems and proposed changes and go through them with you.

  3. 03

    Apply changes

    Changes go in at an agreed time. Risky changes are made in Safe Mode, so the router reverts if we lose the connection.

  4. 04

    Test and handover

    We test internet, VPN, failover and access rules, then hand over documentation and credentials.

MikroTik Setup: frequently asked questions

We lost the MikroTik password. Can you help?

Yes, if you have physical access to the device. It usually needs a reset and a fresh config, so we first go through the services and settings you rely on. If an old backup exists, the job is shorter.

Do you set up MikroTik hotspot for guest Wi-Fi?

Yes. We configure the MikroTik hotspot with a login page, time or data limits and per-user speed limits. For a large number of users, authentication can be moved to User Manager or a RADIUS server.

Do you offer ongoing MikroTik support?

Yes, under a support contract. RouterOS updates, log reviews and config backups are done on a schedule, and response times are set in the agreement.

Related searches

  • MikroTik configuration
  • MikroTik support
  • MikroTik router
  • MikroTik hotspot
  • MikroTik load balancing
  • MikroTik VPN

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.