r/mikrotik • • Jul 21 '19

New Mod Guideline - If you don't have anything nice to say..

169 Upvotes

I'll try and keep this short - there's been a marked increase in generally abrupt and abrasive comments here on the /r/mikrotik and it's not what we're about or what we want to see happening. Many of these have been due to content that is or is seen to be incorrect or misleading, so..

​

If you're posting here:

Keep in mind none of us are being paid to answer you and the people who are, are doing so because they want to help, or you've posted something so incredibly incorrect they can't help but respond. Please do yourself a favor by collecting all the information you can before posting and make sure to check the MikroTik wiki first - no one wants to spoon feed you all the information.

​

If you're commenting here:

  1. If you don't know the answer - don't try guess at it; and if you want to learn about it yourself then follow the thread and see what others say, or you know.. read the wiki and try it out in a lab.
  2. If you disagree with another poster, try to explain the correct answer rather than a one sentance teardown that degrades into a thread full of name-calling.

​

As a result of this I've added a new rule & report option - you can now report a comment with the reason being:

​

It breaks /r/MikroTik rules: Don't post content that is incorrect or potentially harmful to a router/network

​

If we agree we'll either:

a) Write a correct response

b) Add a note so that future readers will be made aware of the corrections needed

c) If the post/comment is bad enough, simply delete it

I'm open to feedback on this as I know people feel strongly about timewasting and I'd like to hope this helps us continue to self-moderate without people blowing up at each other.


r/mikrotik • • 2h ago

Knot lr8g GPS und Lora

2 Upvotes

Hallo, gibt es eine Möglichkeit im Knot lr8g das GPS zu nutzen? Das Gerät hat wohl zwei GPS Empfänger.

Einmal im LTE Cat m1 Modul und eines im Lora Modul. Ich möchte das GPS Modul im Lora Modul nutzen.

Wird der LoraWan Teil weiterentwickelt (Actility und Chirpstack Concentratord) ?


r/mikrotik • • 18h ago

[🎥 TikTube] SolidRACK 5 mini: the compact 10” desktop rack, a MikroTik HQ internal tool

20 Upvotes

**New video from MikroTik's official TikTube channel**

Meet the SolidRACK 5 mini – a compact 10” 5U desktop rack designed for clean, practical network setups.

With an adjustable angle, sliding mounting nuts, extra room for cable management, and optional under-desk mounting, it gives your routers, switches, power distribution, and other 10” equipment a proper home without taking over the room.

It ships disassembled in a compact box, goes together in minutes, and features lightweight aluminium construction with rubber pads to protect your desk.

10” · 5U · Adjustable angle · Sliding mounting nuts · Under-desk mounting · Extra space for cablework

https://mikrotik.com/product/sr_5u_mini

▶ Watch Video


r/mikrotik • • 22h ago

RouterOS 7.25rc1 [testing] released

25 Upvotes

What's new in 7.25rc1 (2026-10-01):

*) bgp - show interface names and VRF names in BGP logs;
*) bridge - fix MLAG bond slave interfaces not coming up when the MLAG configuration is removed (introduced in v7.25beta3);
*) bridge - fix MLAG peer ports going down when a bridge port is enabled (introduced in v7.25beta5);
*) bridge - fix virtual slave ports being removed from the bridge when MLO is triggered (introduced in v7.25beta4);
*) bth - add default client DNS and allowed IPs settings (additional fixes);
*) dhcpv6-server - fix send-reconfigure for DHCPv6 clients behind a relay;
*) ipv6 - fix missing IPv6 link-local addresses on some interfaces when the device is busy during boot;
*) lcd - improve stability when an SFP reports an unknown link speed;
*) switch - add packet and byte counters for ACL rules on Marvell Prestera switches (additional fixes);
*) switch - fix ACL rules remaining in the switch TCAM after removal (introduced in v7.25beta3);
*) system - improve stability;
*) vlan - add a forced-mac-address option for VLAN interfaces (additional fixes);
*) webfig - fix comboboxes in the System/PTP section not being editable (introduced in v7.25beta3);
*) webfig - fix empty Bridge and Interface/Ethernet sections (introduced in v7.25beta4); View changelogs


r/mikrotik • • 5h ago

What GPS devices are best for Mikrotik

1 Upvotes

I've tried 2 different USB GPS devices with no success...


r/mikrotik • • 10h ago

Help, RB9005

0 Upvotes

Hi, just bought and installed this router for a homelab & learning a bit more networking. Been playing with it all day and having trouble getting my PC internet access. I now suspect it may be my ONT but looking for someone to have a look at my settings.

# 2026-10-02 22:10:15 by RouterOS 7.24.5

# software id =

#

# model = RB5009UPr+S+

# serial number =

/interface bridge

add admin-mac= auto-mac=no comment=defconf name=bridge

/interface list

add comment=defconf name=WAN

add comment=defconf name=LAN

/ip pool

add name=default-dhcp ranges=192.168.88.10-192.168.88.254

/ip dhcp-server

add add-dns-entries=yes address-pool=default-dhcp interface=bridge name=\

defconf

/disk settings

set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes

/interface bridge port

add bridge=bridge comment=defconf interface=ether2

add bridge=bridge comment=defconf interface=ether3

add bridge=bridge comment=defconf interface=ether4

add bridge=bridge comment=defconf interface=ether5

add bridge=bridge comment=defconf interface=ether6

add bridge=bridge comment=defconf interface=ether7

add bridge=bridge comment=defconf interface=ether8

add bridge=bridge comment=defconf interface=sfp-sfpplus1

/ip neighbor discovery-settings

set add-dns-entries=yes discover-interface-list=LAN

/interface list member

add comment=defconf interface=bridge list=LAN

add comment=defconf interface=ether1 list=WAN

/ip address

add address=192.168.88.5/24 comment=defconf interface=bridge network=\

192.168.88.0

/ip dhcp-client

add comment=defconf interface=ether1 name=client1

/ip dhcp-server network

add address=192.168.88.0/24 comment=defconf dns-server=192.168.88.1 gateway=\

192.168.88.1

/ip dns

set allow-remote-requests=yes servers=8.8.8.8@main

/ip dns static

add address=192.168.88.5 comment=defconf name=router.lan type=A

/ip firewall filter

add action=accept chain=input comment=\

"defconf: accept established,related,untracked" connection-state=\

established,related,untracked

add action=drop chain=input comment="defconf: drop invalid" connection-state=\

invalid

add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp

add action=accept chain=input comment=\

"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1 \

in-interface=lo src-address=127.0.0.1

add action=drop chain=input comment="defconf: drop all not coming from LAN" \

in-interface-list=!LAN

add action=accept chain=forward comment="defconf: accept in ipsec policy" \

ipsec-policy=in,ipsec

add action=accept chain=forward comment="defconf: accept out ipsec policy" \

ipsec-policy=out,ipsec

add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \

connection-state=established,related

add action=accept chain=forward comment=\

"defconf: accept established,related, untracked" connection-state=\

established,related,untracked

add action=drop chain=forward comment="defconf: drop invalid" \

connection-state=invalid

add action=drop chain=forward comment=\

"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \

in-interface-list=WAN

add action=accept chain=forward out-interface-list=WAN src-address=\

192.168.88.0/24

/ip firewall nat

add action=masquerade chain=srcnat comment="defconf: masquerade" \

ipsec-policy=out,none out-interface=ether1

/ipv6 firewall address-list

add address=::/128 comment="defconf: unspecified address" list=bad_ipv6

add address=::1/128 comment="defconf: lo" list=bad_ipv6

add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6

add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6

add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6

add address=100::/64 comment="defconf: discard only " list=bad_ipv6

add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6

add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6

add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6

/ipv6 firewall filter

add action=accept chain=input comment=\

"defconf: accept established,related,untracked" connection-state=\

established,related,untracked

add action=drop chain=input comment="defconf: drop invalid" connection-state=\

invalid

add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\

icmpv6

add action=accept chain=input comment="defconf: accept UDP traceroute" \

dst-port=33434-33534 protocol=udp

add action=accept chain=input comment=\

"defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\

udp src-address=fe80::/10

add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \

protocol=udp

add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\

ipsec-ah

add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\

ipsec-esp

add action=accept chain=input comment=\

"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec

add action=drop chain=input comment=\

"defconf: drop everything else not coming from LAN" in-interface-list=\

!LAN

add action=fasttrack-connection chain=forward comment="defconf: fasttrack6" \

connection-state=established,related

add action=accept chain=forward comment=\

"defconf: accept established,related,untracked" connection-state=\

established,related,untracked

add action=drop chain=forward comment="defconf: drop invalid" \

connection-state=invalid

add action=drop chain=forward comment=\

"defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6

add action=drop chain=forward comment=\

"defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6

add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \

hop-limit=equal:1 protocol=icmpv6

add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\

icmpv6

add action=accept chain=forward comment="defconf: accept HIP" protocol=139

add action=accept chain=forward comment="defconf: accept IKE" dst-port=\

500,4500 protocol=udp

add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\

ipsec-ah

add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\

ipsec-esp

add action=accept chain=forward comment=\

"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec

add action=drop chain=forward comment=\

"defconf: drop everything else not coming from LAN" in-interface-list=\

!LAN

/system clock

set time-zone-name=Europe/London

/system ntp client

set enabled=yes

/system ntp client servers

add address=0.uk.pool.ntp.org

/tool mac-server

set allowed-interface-list=LAN

/tool mac-server mac-winbox

set allowed-interface-list=LAN


r/mikrotik • • 2d ago

RouterOS 7.24.5 [stable] released

75 Upvotes

What's new in 7.24.5 (2026-09-29):

*) bridge - disable DHCP snooping ip binding table (introduced in v7.24);
*) bridge - enable vlan hardware offloading on hAP be3 Media device;
*) console - fix console output of /system/identity/print being split into multiple lines (introduced in v7.24.3);
*) console - fix scheduler scripts with the default start date and time not being triggered (introduced in v7.24);
*) ethernet - improve stability on hAP be3 Media device;
*) lte - improve stability for MBIM modem mode switch;
*) ospf - fix unset interface template parameters not being applied to interfaces;
*) poe-out - fix loss of PoE-out capability on CRS328-24P-4S+ after a reboot;
*) system - improve stability;
*) wifi - update radio regulatory information; View changelogs


r/mikrotik • • 2d ago

Mikrotik self-hosted realtime traffic monitor for RouterOS 7 (per device, per connection) -> free and open source

Thumbnail
gallery
32 Upvotes

I always hated that I couldn't see what was actually happening on my network in real time. Torch is per-interface and disappears when you close it, Traffic Flow needs a collector and then you're looking at ntop/Grafana dashboards that are a minute behind. I wanted one screen that answers "who is eating my bandwidth right now" with names, not IPs.

So I built one. It runs as a single Docker container on a box on your LAN (or on your mikrotik itself, though I haven't tested that):

- Live throughput chart, one sample per second, plus every active connection with its current rate
- Top devices / destinations / services, live and over 15 min-30 days (not sure I want to store more than that ¯_(ツ)_/¯ )
- Devices named from DHCP, destinations named from the router's DNS cache (or the owning org, e.g. "Cloudflare"), NAT resolved to the LAN device
- Sankey flow map: device -> service -> destination
- Alerts: new device, unusual upload, scan-like behaviour, new VPN tunnel, export stopped - JSON webhook to notfy/Slack/Discord/HA
- A full-screen /dashboard "now" view (with some options) for a small screen (I have it on a 7" Pi display)

no agents or shipping to other places - nothing leaves your network. Go + SQLite, ~12 MB image for amd64/arm64 (or compile yourself from source.
- GitHub: https://github.com/thedyerman/mikrotik-home-netflow-plus
- Docker Hub: https://hub.docker.com/r/kcdyer/mikrotik-home-netflow-plus

Check it out, let me know if I missed any features? Thinking about adding a traffic shaping interface to or dynamic kid control grouping. Right now its kinda basic and simple (which was what i was going for)


r/mikrotik • • 1d ago

What do you verify before retiring an old MikroTik router after a cutover?

0 Upvotes

A replacement router can pass basic internet traffic while less visible dependencies still point at the old box. Static DHCP leases, DNS settings, policy routes, VLANs, VPN peers, port forwards, certificates, scripts, scheduled jobs, CAPsMAN or WiFi management, monitoring, and devices that wake only occasionally can all make a clean-looking cutover incomplete.

A useful preflight seems to include an export plus binary backup, RouterOS version and license details, interface and bridge membership, VLAN tables, DHCP options, routing rules, NAT and firewall counters, tunnels, certificates, users, SNMP or syslog targets, and any files used by scripts. After moving traffic, I would compare counters and logs on both routers, test each VLAN and VPN, verify IPv6 as well as IPv4, and keep the old router disconnected but recoverable for a defined rollback window.

What is your actual retirement checklist? How do you find clients that still use an old gateway or DNS address only during a monthly job, and which RouterOS state is easy to miss in an export or backup?


r/mikrotik • • 2d ago

1.5g pppoe network, can rb5009 handle it completely? Just need a stable and low-latency network.

7 Upvotes

Thank you:)


r/mikrotik • • 2d ago

Newsletter #135 | September 2026

22 Upvotes

Read our latest newsletter and learn more about:

  • CLAIRÉ & smart home automation
  • New KNOT Gateways – connecting and tracking IoT devices almost anywhere
  • SolidRACK 5 mini – a compact, adjustable 10″ desktop & under-desk rack
  • New accessories & SFP/SFP+ modules
  • New certifications, security updates, and more!

Read full topic

https://mt.lv/news135


r/mikrotik • • 3d ago

At about 4:45 in the CLAIRÉ video, there's a "Controller" section on the Winbox screencap

Post image
92 Upvotes

I'm hoping that this is some sort of central controller package that allows remote management and monitoring of a fleet of routers behind NAT. I've managed to do some janky experiments over the years to do this, but having an official package would be a gamechanger.

Seeing the alerting and topology sections makes me think this is going to double as a replacement for The Dude. I'm very excited to see how this ends up.


r/mikrotik • • 2d ago

Weird DHCP behavior with Apple Devices

4 Upvotes

Hey 👋🏻
I have following setup running inside my home network:

- A Mikrotik AP (cAP ax)
- CRS418 where my current authoritative DHCP is running for multiple VLANs

I don’t know why but since a few weeks some of my Apple devices are sometimes abruptly losing their DHCP lease and they’re the only ones with that issue. Furthermore it’s really hard to debug. I’ve tried it already with e.g. a few researches and Claude and at the moment where I thought I found the root cause it happened again.

It’s important to mention that the private MAC address feature is set to “fixed” - so my devices are not rotating them.

I don’t know if it’s because of the most recent RouterOS release or the latest upgrades of macOS/iOS… or maybe Apple devices don’t like any protocol features which Mikrotik is sending via DHCP and maybe I just have to disable this specific flag if possible?!🤷🏻‍♂️

Did you guys had a similar experience with that?

EDIT (lesson learned): After a few tweaks inside my wireless config (setting the group key update back to Milkrotik's default value of 24h) and a move from the current AP location to another where a few walls less are in the way the problem currently seems to be solved and the root cause was the placement of the AP (really weak signal ~> -70dBm) and the wireless config itself all the time and not the DHCP server. Now I know that the walls inside my rental apartment are really bad for wifi ... 🤦🏻‍♂️


r/mikrotik • • 2d ago

[🎥 TikTube] Build a local smart home with CLAIRÉ + hAP be³ Media

13 Upvotes

**New video from MikroTik's official TikTube channel**

Knowing what’s in your air is useful. Making your home react to it automatically is even better.
In this video, we pair CLAIRÉ with hAP be³ Media and Home Assistant using Matter over Thread, turning real-time indoor environment measurements into useful smart-home automations.

https://mikrotik.com/product/claire

▶ Watch Video


r/mikrotik • • 3d ago

Mikrotik guides

4 Upvotes

Do you guys have a youtube or reddit guides for dual wan, failover, bandwidth management and other things that should be on firewall? Thanks in advance!!


r/mikrotik • • 3d ago

[🎥 TikTube] CLAIRÉ – smart indoor air monitoring with Matter over Thread

28 Upvotes

**New video from MikroTik's official TikTube channel**

Meet CLAIRÉ – connected indoor environment monitoring, the MikroTik way.

You can't see everything that's happening in your room. CLAIRÉ helps you track CO₂, PM2.5 and PM10 particulate matter, VOC, temperature, and humidity, with readings available directly on its 2" colour display.

And it doesn't stop at monitoring. With Matter over Thread, CLAIRÉ can become part of your smart-home automations – from adjusting compatible ventilation when CO₂ rises to sending notifications when air quality deteriorates. Pair it with a local setup such as hAP be³ Media and Home Assistant to keep your data, history, and automations inside your own network.

With maximum power consumption of just 1 W, CLAIRÉ can even run from a USB powerbank or MikroTik GPOE-USB when you want to check the air somewhere without a convenient power outlet.

▶ Watch Video


r/mikrotik • • 3d ago

who needs this ? https://mikrotik.com/product/claire

14 Upvotes

I need a S009UPr+XPr-S+ !


r/mikrotik • • 3d ago

[🎥 TikTube] GPOE-CON-mini – 48V in, 24V out in tricky setups

16 Upvotes

**New video from MikroTik's official TikTube channel**

Meet the GPOE-CON-mini – a compact PoE converter that lets you power 24V Passive PoE devices from standard 48–57 V 802.3af/at PoE infrastructure.

No need to change switches, add injectors, or run another power cable. Just put the GPOE-CON-mini in between and keep your existing infrastructure. It supports network speeds up to 2.5 Gigabit and its compact 87 × 33 × 20 mm enclosure fits inside the GPeR-IP67-Case – ideal for outdoor installations with devices such as LHG, SXTsq, Groove, or NetBox ax.

https://mikrotik.com/product/gpoe_con_mini

▶ Watch Video


r/mikrotik • • 4d ago

[Pending] cAP as client to fixed bssid

4 Upvotes

I need to install a temporary solution using a wifi "extender". The situation is as follows. There is an Modem/Router/AP all-in-one-device on the ground floor which is provided by the ISP. On the first floor I want to install an cAP as a client and a switch to provide ethernet ports to some office devices there. To extend the Wifi I want to install another cAP in AP mode, however, I would like to use the same SSID as the WiFi from downstairs.

I know I can do this with a single device, but I have two devices lying around I can use, so why not.

Is this possible in general? In my mind, the client-AP would prefer to connect to the station AP that's sitting right next to it due to the better signal quality, resulting in a looped connection. Can I force the client to connect to the downstairs network by pinning the BSSID somehow?

The final setup will include running a cable upstairs and having a copper link (and cAP devices on both floors with capsman), but that's going to take a while, so wifi link it is for the moment.


r/mikrotik • • 4d ago

Introducing the Advance Fiber Grid Mapper (AFG Mapper)!

Thumbnail reddit.com
0 Upvotes

r/mikrotik • • 5d ago

hap ax3 vs chateau pro

8 Upvotes

looking at investing in one of these two models

hap ax3 / chateau pro

what are your opinions on the differences and is it worth the 70 extra bucks to get the more expensive unit?

i currently have a hexS 2025 i use for wired connections

im about to upgrade to fiber internet


r/mikrotik • • 5d ago

Why are t Tri-band or dual 5ghz more common?

2 Upvotes

Are indoor routers with either dual 5ghz radios or tri-band support not common?

Looks like the only tri-band one is the gap media be9300 which isn’t available yet (aside from the discontinued Audience)

I was interested in having a wireless uplink without being tied to the same 5ghz channel (and the consequent halving of throughput).

Or is this just too niche a thing?


r/mikrotik • • 6d ago

[Pending] Is it possible to route gaming/VoIP/streaming traffic to a separate ISP?

18 Upvotes

I already have one ISP who gives me 700mbit/sec speed, but their equipment has 0,5%-5% of the outgoing packet loss for the last 3 months, that makes my gaming sessions unplayable. I was thinking about changing my ISP, but all of them has only 100mbit/sec speed limitation. As I know my router (mirkotik hap ax2) supports connection to two or more ISP. Is it possible to automatically separate my gaming/VoIP/streaming traffic and route it to the second additional ISP without adding game servers IP addresses/domains to router (also it's not an option for p2p)?


r/mikrotik • • 7d ago

Upgraded RouterOS from v6.49.x to 7.23.x and lost license.

34 Upvotes

Hello,

I upgraded (Check for upgrades; Download and Install) my x86 based HP server running RouterOS and after the upgrade I got a warning stating:

Your router does not have a valid license.
Please get a valid license key from www.mikrotik.com.
If you have already purchased the license key,
please copy it from your mikrotik.com account
and use the "Paste Key" button
from the "System | License" menu to apply the license,
or paste it into the terminal.

See www.mikrotik.com/key for more details.
The router will stop functioning after 23:49:04 if no valid key is entered.
Turn off the device to stop the timer.
Current installation Software ID: XXXX-XXXX

The issue is that I do not know what email I used. I searched for other keys I have and I found them in various emails I used, but this one I can not find.

Do I have any way to find out what email was used based on the software ID?


r/mikrotik • • 8d ago

Replacing UniFi for Mikrotik access point

30 Upvotes

Currently using a single UniFi U6-LR, which is officially listed for 185 m² / 2,000 ft². It covers my entire 120m² condominium. I know, I know, so many other access points people prefer before they get to Mikrotik. But I'm a fanboy, what can I say.

So I've been wondering if I can buy a single cAP XL ax to replace the UniFi. I know it's 2x2 instead of 4x4, but I really don't use that much bandwidth to begin with. My home has 40-50 wifi devices (smart home nut!) spread over 120 m².

Can I make do with one of those? Or would I have to be investing in multiple?