~/tags
Routeros
- 2026-04-03Final security checklist for a MikroTik network: baseline, VLANs, firewall, Wi-Fi, IPv6, VPN, DNS, monitoring, backups, and DR.
- 2026-04-02Disaster recovery for a MikroTik network: lockout recovery, hardware replacement, runbook, documentation, and restore checks.
- 2026-04-01Automated backups for MikroTik: binary backup, export, scheduler, external storage, retention, and restore testing.
- 2026-03-31Monitoring and alerts for MikroTik: WAN, VPN, CPU/RAM, DHCP pools, DNS, backups, logs, SNMP, and actionable alerts.
- 2026-03-30Logging strategy: which events to write, where to send them, and how not to drown the router in logsLogging strategy for MikroTik: security events, firewall prefixes, remote syslog, script logs, and noise control.
- 2026-03-29Dual WAN on MikroTik: route distance, recursive checks, NAT, DNS, WireGuard, failover/failback, and notifications.
- 2026-03-28QoS and traffic shaping on MikroTik: bottleneck shaping, queues, CAKE/FQ-CoDel, FastTrack, and latency testing.
- 2026-03-27How to use FastTrack on MikroTik without breaking QoS, mangle, policy routing, and observability.
- 2026-03-25DNS policy on MikroTik: DNS cache, DoH upstream, enforcement by VLAN, and the limits of blocking client DoH.
- 2026-03-24Configuring WireGuard on MikroTik for road-warrior and site-to-site scenarios with limited VLAN access.
- 2026-03-23Enabling IPv6 on MikroTik deliberately: prefix delegation, RA/SLAAC, DNS, and a separate firewall for VLANs.
- 2026-03-22Centralized Wi-Fi through CAPsMAN in RouterOS 7: SSID, security profiles, VLAN per SSID, and management VLAN for APs.
- 2026-03-21How to design mDNS and service discovery between VLANs without undoing IoT, Guest, and LAN isolation.
- 2026-03-20Isolating IoT in a separate VLAN with DHCP/DNS, firewall policy, address-lists, and controlled access from trusted segments.
- 2026-03-19Guest Wi-Fi as a separate VLAN: SSID, DHCP/DNS, firewall internet-only policy, and blocking LAN access.
- 2026-03-18A look at srcnat, dstnat, port forwarding, hairpin NAT, and split DNS on MikroTik with a focus on minimal attack surface.
- 2026-03-17A baseline firewall hardening model for MikroTik: input, forward, WAN drop, management access, and rules between VLANs.
- 2026-03-16The L3 foundation for VLANs in RouterOS 7: gateway addresses, DHCP pools, DNS cache, routes, and interface lists.
- 2026-03-15Configuring bridge VLAN filtering in RouterOS 7: trunk, access, PVID, bridge VLAN table, and lockout protection.
- 2026-03-14Planning VLAN IDs, subnets, gateways, DHCP, trunk/access ports, and an access matrix before configuring MikroTik.
- 2026-03-13How to use MikroTik as the core router and security boundary between WAN, VLANs, VPN, and internal segments.
- 2026-03-12RouterOS 7 baseline setup: access, users, services, updates, time, backup/export, and minimal management protection.
- 2026-03-11Practical MikroTik router, switch, and Wi-Fi device selection for VLANs, firewall, WireGuard, and network growth.
- 2026-03-10Target architecture for a managed MikroTik RouterOS 7 network with VLANs, a Wi-Fi access layer, firewall, and VPN.