// Engineering Log
MikroTik: what is this router and why is it useful for small businesses
Published on 2026-09-22
// Fast route
This article belongs to the topic Networking and routing.
For a small office people usually buy a consumer router from TP-Link, ASUS, or Keenetic. While there are five people and one Internet link, that’s enough. When a second provider appears, remote employees, guest Wi-Fi, IP telephony and a branch office appear, a consumer device becomes limited. Then they look at MikroTik routers: they cost only a bit more than consumer devices but offer a feature set comparable to enterprise equipment.
What is MikroTik and RouterOS
MikroTik is a Latvian company that produces routers, switches and wireless equipment. The hardware is sold under the RouterBOARD brand, but the main thing in MikroTik products is the operating system RouterOS. It is built on the Linux kernel and is the same across all models: from the desktop hAP to the rackmount CCR. Once you learn RouterOS on one device, you’ll be able to configure any other.
The current branch is RouterOS 7. As of 16 September 2026 the latest stable version is 7.24.4, the long-term (LTS) version is 7.23.7. The 6.x branch is supported only with fixes; new devices are released on RouterOS 7.
What RouterOS can do:
- routing — static and dynamic (OSPF, BGP, RIP), multiple routing tables (VRF);
- firewall — filtering, NAT, address lists, connection limits;
- traffic management (QoS) — queues, priority for telephony and video calls, per-user bandwidth limits;
- VPN — WireGuard, IPsec/IKEv2, OpenVPN, L2TP, SSTP, EoIP, VXLAN;
- link redundancy — failover to a second provider and load balancing;
- Wi-Fi — access point, bridge, centralized access point management (CAPsMAN);
- HotSpot — guest access with a login page;
- containers — run small services directly on the router;
- scripts and scheduler — automate routine tasks.
You can manage the router in three ways: the WinBox application (for Windows, macOS and Linux), the WebFig web interface, and the command line via SSH. All three show the same settings.
RouterOS licenses
The RouterOS license is tied to the device and is already included in its price. The license level determines limitations, not the feature set:
| Level | Where found | Limitations |
|---|---|---|
| 3 | subscriber wireless devices | client-mode operation, up to 200 tunnels |
| 4 | most desktop routers | up to 200 PPPoE/PPTP/L2TP tunnels and 200 HotSpot users |
| 5 | operator-class devices | up to 500 tunnels and 500 HotSpot users |
| 6 | CCR series; for x86 bought separately | no limitations |
Level 4 is enough for a small office: 200 concurrent VPN connections is headroom for years.
CHR (Cloud Hosted Router) is licensed separately — RouterOS for a virtual machine. The free version is limited to 1 Mbit/s per interface; perpetual licenses P1, P10 and P-Unlimited increase the limits to 1 Gbit/s, 10 Gbit/s and unlimited, respectively. CHR is convenient to run on a VPS as a central point for VPN between offices.
Hardware series
- hAP — desktop routers with built-in Wi-Fi for a small office or home; hAP ax² and hAP ax³ models support Wi-Fi 6.
- RB (for example, RB5009) — high-performance desktop and rackmount routers without Wi-Fi, to which separate access points are attached.
- CCR — rackmount routers for heavy loads and carriers.
- CRS — managed switches; run either RouterOS or simplified SwitchOS.
- cAP, wAP — access points for ceiling and outdoor use.
Why MikroTik is convenient for small businesses
One device instead of several. A MikroTik router simultaneously acts as a firewall, VPN server, DHCP and DNS server, access point and guest network controller. For an office of 10–30 people, often one hAP or RB5009 and a couple of access points are enough.
Enterprise features at a consumer-router price. Failover, site-to-site VPN, separate networks for guests and cameras (VLANs), and priority for telephony — consumer routers either don’t have these or implement them partially.
Remote work. WireGuard in RouterOS 7 is configured with a few commands, works quickly and is supported on Windows, macOS, Android and iOS:
/interface/wireguard add listen-port=13231 name=wg-office
/interface/wireguard/peers add interface=wg-office \
public-key="<employee public key>" allowed-address=10.10.10.2/32Traffic management. For IP telephony and video calls you can allocate priority, and for the guest network you can limit speed so it doesn’t interfere with work.
Scaling. As the company grows you replace the router with a more powerful model and transfer the configuration: the configuration logic is the same across models.
Who MikroTik is for, and who it’s not for
MikroTik is suitable if:
- the office has more than one Internet link or needs redundancy;
- employees connect to the office network from home;
- there are branches that need to be joined into a single network;
- you need to segment the network: employees, guests, cameras, phones;
- there is a specialist, in-house or contracted, who will maintain the network.
MikroTik is not the best choice if there’s no one to take care of it. RouterOS requires understanding of networking principles, and a mistake in firewall rules can expose the router to attack from the Internet. If you need a network that is managed mainly through a visual interface, consider systems with centralized management, for example UniFi.
Minimal secure setup
A new MikroTik router ships with a factory configuration: a basic firewall, NAT, and a DHCP server for the LAN. On new models the administrator password is unique and printed on a sticker; on old devices the admin account has no password. Immediately after connecting, perform several steps recommended by MikroTik.
- Update RouterOS and the bootloader.
/system package update check-for-updates
/system package update installAfter reboot update the bootloader: /system routerboard upgrade and reboot again.
- Create your own administrator and disable the default one.
/user add name=netadmin password="<long password>" group=full
/user disable admin- Disable unnecessary services and restrict management access. Telnet, FTP and the HTTP web interface are usually not needed in the office; WinBox and SSH should be available only from the local network:
/ip service disable telnet,ftp,www,api,api-ssl
/ip service set winbox address=192.168.88.0/24
/ip service set ssh address=192.168.88.0/24- Disable MAC-based access and neighbor discovery from the provider side. The factory configuration contains LAN and WAN interface lists; keep these functions only for LAN:
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN
/ip neighbor discovery-settings set discover-interface-list=LAN
/tool bandwidth-server set enabled=no
/ip dns set allow-remote-requests=noDo not run the last command if the router provides DNS to local network clients: in that case allow requests, but make sure port 53 is closed from the WAN side by firewall rules.
- Save the configuration. Backups come in two types:
/system backup save name=office-2026-09 password="<password for file>"
/export file=office-2026-09The binary backup (.backup) restores the router completely, but only on the same device. The text export (.rsc) is human-readable and suitable for transferring settings to another model; in RouterOS 7 passwords are not included in it by default. Download both files from the router and store them separately.
For remote management do not open WinBox to the Internet: connect to the router via VPN.
Common mistakes
- Management is open from the Internet. WinBox, the web interface or SSH are accessible from the provider side — this is the main reason MikroTik routers get hacked. Management access should be only from the local network or via VPN.
- The router hasn’t been updated for years. Vulnerabilities in RouterOS are found and patched regularly, and old versions become an easy target.
- Default firewall rules were removed. Default rules are dropped when starting from a clean configuration and new ones are not created. If you start from a clean config, first configure the
inputchain. - Open DNS or proxy. The router answers DNS queries or acts as a proxy for the whole Internet and is used in other people’s attacks.
- No backup. After a failure or a bad update the configuration has to be recreated from memory.
Shipments to Russia
Since February 2022 MikroTik has stopped shipping hardware and selling licenses to Russia and Belarus; licenses issued earlier remain valid. There is no official manufacturer support in Russia, so before buying clarify warranty and replacement conditions with the seller.
Further reading
- Full guide to configuring MikroTik for office and home
- OpenVPN server on MikroTik RouterOS
- Native reverse proxy in RouterOS 7.22+
- Traffic prioritization on MikroTik
- Port knocking on MikroTik
If you need MikroTik configured for office tasks — redundant link, VPN for employees, guest network — see the MikroTik setup service.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
Huge thanks to Mikhail for the work — I'm very pleased with the result. Special thanks for his recommendations during setup: from my rather muddled brief (I know little about servers), Mikhail, through clarifying questions and suggestions, formed a clear understanding of what the final build would accomplish and how best to organize everything. I recommend him!
Many thanks to Mikhail for the work, I am very pleased with the result. I especially thank him for the recommendations during the setup process — from my rather muddled brief (and I know little about servers) Mikhail, …
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-07-21 · ★ 5/5
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed what we'd been racking our brains over for days! I'm sure this won't be the last time we rely on his boundless professionalism.
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed for us what we had been scratching our heads over for days! I'm sure this won't be the first time we make use of his boundless …
MikroTik hAP router setup. I'll configure a MikroTik Wi-Fi router for you.
2025-05-28 · ★ 5/5
A professional approach to the job!
Professional approach to the job!
MikroTik hAP router setup. I'll set up a MikroTik Wi-Fi router for you.
2025-03-31 · ★ 5/5
Knows their stuff, gets things done. Everything was prompt and to the point; I was satisfied with the collaboration.
Knows, can, does. Everything was prompt and to the point; I was satisfied with the collaboration.
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-03-14 · ★ 5/5
Thanks! We set up the router according to my technical specification, with a full explanation of what we're doing.
Thank you! The router was configured according to my technical specification, with a full explanation of what we are doing
MikroTik hAP router setup. I'll configure a MikroTik Wi‑Fi router for you.
2025-03-09 · ★ 5/5
Everything's great! Thanks! I recommend it.
Everything's great! Thank you! I recommend it
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related