In short
MikroTik configuration is the setup of routing, firewall, NAT, VPN, dual WAN load balancing and wireless on RouterOS, the operating system that runs on MikroTik devices. It suits SMEs looking for a cost-effective but capable router or branch device. CybUp hardens the default configuration, writes the firewall and VPN rules, brings Wi-Fi under central management with CAPsMAN and hands everything over documented.
What does MikroTik configuration cover?
A MikroTik setup covers updating RouterOS, building the interface and VLAN structure, writing firewall and NAT rules, bringing up VPN tunnels, balancing two internet lines where needed and configuring wireless. Management is done through WinBox, WebFig or the command line; we apply changes from the command line so they are repeatable and easy to back up.
Beyond that, RouterOS has plenty more to offer, including hotspot (captive portal), bandwidth management with queues, OSPF and BGP. You do not need to switch it all on. Working out which features the project will actually use, and configuring only those, keeps the device both secure and understandable.
“Start by upgrading your RouterOS version. Some older releases have had certain weaknesses or vulnerabilities, that have been fixed.”
Is the MikroTik default configuration secure?
The default configuration is a good starting point, but not enough on its own. According to MikroTik’s own documentation, the factory firewall blocks connections from the WAN side and that rule is there on purpose; if you need remote management, the advice is to use a VPN such as WireGuard rather than open a port to the internet (MikroTik: Securing your router). The most common mistake we find in the field is exactly that rule having been deleted to allow remote access.
These are the hardening steps we apply during setup:
- Upgrade RouterOS to the current stable release
- Disable the default “admin” user and create named accounts with passwords of at least 12 characters
- Turn off MAC-Telnet, MAC-WinBox, MAC-Ping, proxy, SOCKS, UPnP and remote DNS requests unless they are needed
- Make management services (WinBox, SSH) reachable from the management network only
- Disable unused interfaces
“To prevent remote access to your device, there is a pre-configured firewall that blocks WAN (internet side) connections. This is intentional, please do not remove these rules unless you're absolutely certain that the connection is secure.”
How do you write MikroTik firewall rules?
In the RouterOS firewall, traffic addressed to the router itself is filtered in the “input” chain, and traffic passing through it in the “forward” chain. A solid rule set opens by accepting established and related connections and dropping invalid packets; after that, only explicitly permitted traffic gets through, and everything else is dropped at the end.
Address lists cut down the number of rules: we define lists such as “admin-pcs”, “servers” and “branches” and write the rules against them. In a 25-person architecture practice, say, the guest Wi-Fi, the staff network and the NAS holding the drawings sit in separate VLANs. The forward chain drops everything from the guest network to the internal networks, and only the file-sharing ports are open from the staff network to the NAS.
MikroTik VPN: WireGuard or IPsec?
Choose WireGuard if both ends are MikroTik or a few administrators need remote access, and IPsec (IKEv2) if there is another vendor’s firewall at the far end. WireGuard is built into RouterOS 7, with a default listen port of 13231 and a default MTU of 1420 (MikroTik: WireGuard). Its configuration is short, which leaves less room for mistakes.
IPsec is the common language for talking to a FortiGate, pfSense or a cloud virtual network gateway (MikroTik: IPsec). The encryption and key exchange parameters must match exactly at both ends, and most “the tunnel is up but no traffic passes” problems come from there. We design head office to branch tunnels as part of VPN server setup.
How do you load balance two internet lines on MikroTik?
The usual way to balance two lines on a MikroTik is PCC (Per Connection Classifier): every packet in a connection always uses the same line, while different connections are spread across the lines (MikroTik: Per connection classifier). If we classify by source address, each user always goes out through the same line, which avoids trouble with banking and government sites that drop the session when the source IP changes.
Alongside balancing, failover to the other line has to be set up too. Checking whether the modem is up is not enough: when there is an outage inside the provider’s network, the modem carries on answering. So we use recursive routes that check internet targets beyond the line itself. If you need more detailed quality measurement and application-based routing, FortiGate SD-WAN is worth considering.
How do you manage MikroTik Wi-Fi with CAPsMAN?
CAPsMAN lets you manage the wireless settings of several MikroTik access points from one place: SSID, security and channel settings are written once and pushed out to every device (MikroTik: CAPsMAN). When a new access point is added, it picks up its configuration from the centre.
Watch the version differences here. The “WiFi” menu introduced in RouterOS 7.13 manages Wi-Fi 5 wave2 and newer radios, and needs the right driver package for the device (wifi-qcom or wifi-qcom-ac) (MikroTik: WiFi). On networks with a mix of older and newer devices, we plan up front which device will be managed by which CAPsMAN. For floor plans, access point placement and 802.1X, see our enterprise Wi-Fi installation page.
What you receive
- Up-to-date RouterOS with hardened management access
- VLAN structure, firewall and NAT rules, and address lists
- WireGuard or IPsec VPN tunnels
- Dual WAN load balancing and a line failure scenario (where needed)
- Central Wi-Fi management with CAPsMAN (where needed)
- Automatic configuration backups and a handover document
How we work
- 1
Free review
We review your current MikroTik configuration, lines and requirements, and report any security weaknesses in writing.
- 2
Plan
We draw up the VLAN, firewall, VPN and line balancing design and put it to you for sign-off.
- 3
Configuration
We update RouterOS and apply the rules, tunnels and wireless settings.
- 4
Testing
We test line failure, VPN access and access between segments.
- 5
Handover
We hand over the backups, the documentation and the admin accounts.
Frequently asked questions
Is MikroTik good enough for business use?
For routing, firewalling, VPN and dual WAN, it is enough for most SMEs. If you need application identification, SSL inspection and subscription-based threat signatures, a firewall such as FortiGate is a better fit, and the MikroTik can stay on as a router or branch device.
Can you tidy up our existing MikroTik without resetting it?
Yes. We take a full backup of the configuration first and review it. If the rule set is badly tangled, we suggest building a clean configuration in parallel and switching over in a short maintenance window.
How much does MikroTik configuration cost?
We give a written quote after reviewing the scope, and the review is free. The number of devices, VPN tunnels, dual WAN and the Wi-Fi scope determine the work.
Can we open the WinBox port for remote management?
We advise against it. Putting management access behind a VPN such as WireGuard is far safer than a management port exposed to the internet.
Can you set up a VPN between a MikroTik and a FortiGate?
Yes, with IPsec (IKEv2). The encryption, key exchange and network definitions simply need to match exactly at both ends.
Should we upgrade from RouterOS 6 to RouterOS 7?
Yes, for the new features (WireGuard, the new WiFi menu) and the security updates. Some settings change format, though, so we take a backup and check the configuration before the upgrade.
Do you support branches outside Istanbul?
Yes. We work on-site in Istanbul and remotely elsewhere; once a member of your staff has connected the device at the branch, we finish the configuration remotely.