// Engineering Log

RouterOS 7.22: Apps, Built-in Reverse Proxy, and BGP — What Changed and How to Use It

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

RouterOS 7.22 was released on March 9, 2026. The main changes: Apps on top of containers, a built-in reverse proxy, notable BGP improvements and RA guard protection in the bridge. Below is a breakdown according to the official changelog (CHANGELOG). Note that newer versions have been released since: as of September 2026 the current stable branch is 7.24.4 (more about choosing a version — in the article about MikroTik).

Apps on top of containers

Apps in RouterOS are ready-made templates that are deployed in containers. Containers are still there: the /container menu remains and in 7.22 it also received changes. Apps are a layer on top of them that simplifies the installation of typical services.

What changed according to the changelog:

  • added apps jupyter-notebook, livebook, myip and rustfs;
  • added health check for apps;
  • added support for custom apps;
  • on all devices where apps are used, swap is enabled — for performance on models with small amounts of RAM.

Changes in the containers themselves:

  • support for unpacking images in zstd format;
  • the container automatically stops, re-downloads the image and starts if the image was updated in the remote repository or was requested again.

Containers on the router require a separate package and careful attention to resources: RAM and flash storage are small on most models. Anything that functions as a VPN gateway or handles transit traffic should be tested in a lab before updating.

Built-in reverse proxy

7.22 introduced a reverse-proxy, as well as error messages for its rules. It allows publishing internal web services through the router without a separate machine running Nginx or Caddy. The same release added support for HTTP/2 on ARM64 and x86/CHR devices.

This is not a replacement for a full L7 load balancer, but it’s enough to provide access to several internal office panels or a home lab. A step-by-step setup with certificates, split DNS and firewall rules is in the article “Native Reverse Proxy in MikroTik RouterOS 7.22+”.

BGP

Three features were added to BGP in 7.22 that were previously mainly available on carrier-class equipment:

  1. BGP unnumbered — sessions without assigning IPv4 addresses on links between routers (usually based on link-local IPv6 addresses). Fewer /30 and /31 subnets to plan and account for.
  2. Multipath — selection of multiple equal best paths (ECMP) and distribution of traffic between them.
  3. Add-path — sending multiple paths to a neighbor for the same prefix, which speeds up failover.

These functions are useful in networks with multiple links and routers; for redundancy with two providers in a small office, simpler schemes are often sufficient (see the section on Internet redundancy).

Bridge: RA guard and MLAG

  • RA guard — protection against forged IPv6 Router Advertisement messages. An attacker or a misconfigured device on the local network can send such advertisements and divert traffic through itself; RA guard allows them only from trusted ports.
  • MLAG is now configurable per bridge interface separately.

Small but useful changes

  • Console and scripts: commands :continue and :break for loops, :exit to finish a script; word-wise navigation with Ctrl+←/→ and delete word with Ctrl+W.
  • IPv6 in scripts: bit shifts << and >> for IPv6 addresses — handy for slicing subnets.
  • Internet sharing over USB: support for iOS devices and a fix for Google Pixel Pro 8 — a quick way to bring up a backup link.

Should you upgrade

Now the question is not about 7.22, but about the current stable branch, which includes these changes and subsequent fixes. The update procedure is standard:

  1. Make a backup (/system backup save with a password) and export the configuration (/export file=...).
  2. Read the CHANGELOG of all versions between your current and target — especially if you use containers, BGP or non-standard tunnels.
  3. Update a test device or one of the redundant devices first, then the rest.
  4. After updating RouterOS, update the bootloader (RouterBOARD firmware) and reboot the device.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Reviews

Related reviews

I needed to get n8n, Redis, and the database working. I had hired another contractor before and everything kept breaking. I hired Mikhail, and the next day everything was working quickly, like clockwork!

There was a task to get n8n, redis and the database working. I had previously ordered from another contractor, it kept breaking all the time. Ordered from Mikhail, the next day everything started working fast, like …

christ_media

n8n installation on your VPS server. Configuration of n8n, Docker, AI, Telegram

2025-09-24 · ★ 5/5

Experienced buyer

Quick solution — I highly recommend Mikhail as a contractor! I tried to build a similar configuration myself and even followed AI advice, which ended up costing a lot of time and money (due to server downtime). So my advice: hire professionals — it's cheaper =) Thanks to Mikhail for his professionalism.

Quick fix for the problem, I recommend Mikhail as a contractor to everyone! I tried to assemble a similar configuration myself and following advice from neural networks, which resulted in a lot of wasted effort and …

ladohinpy

n8n installation on your VPS server. Configuration of n8n, Docker, AI, Telegram.

2025-08-25 · ★ 5/5

ladohinpy

MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.

2025-07-21 · ★ 5/5

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply