Skip to main content

7 docs tagged with "security"

View all tags

Apps

The Apps menu provides a catalog of pre-configured applications deployable via containers, with automatic RouterOS configuration and support for multiple container registries. It requires Container package installation, physical access for initial setup, and includes security considerations such as certificate verification and hardware device management.

Case studies

Cross-driver wireless case studies for MikroTik RouterOS: practical designs and workflows that apply to both the /interface/wireless and /interface/wifi menus, covering wireless station modes and enterprise wireless security with User Manager.

Container

This page documents MikroTik RouterOS container support, covering configuration, virtual interfaces, storage, and security considerations. It details properties like restart intervals, DNS settings, CPU allocation, and memory limits for running containerized services while warning of security risks.

Port knocking

Port knocking keeps the management ports of a RouterOS router closed until a client connects to a secret sequence of ports; the firewall then adds the client to a trusted address list. Covers the knock rules in the default firewall, knocking from a client, a blacklist against port scans, a passphrase knock with layer 7, and checking the lists.

Securing your router

This page provides security recommendations for MikroTik RouterOS, including upgrading RouterOS versions, changing default usernames and passwords, securing access with firewall rules and VPNs, disabling unnecessary services like MAC-Telnet and Neighbor Discovery, and managing DNS caching to enhance router security.

SNMP

This page documents SNMP configuration in MikroTik RouterOS, covering enabling the service, general settings like contact info and trap configurations, community access rights for SNMPv1/2c/3, and warnings about timeouts when monitoring slow services or OIDs.

SSH brute-force protection

Protect an internet-facing SSH service on RouterOS with firewall rules that count new connections per source address and block a source that opens too many in a short time. Covers what to do before exposing SSH, placing the rules in the default firewall, exempting trusted addresses, IPv6, checking and unblocking, and how many password guesses the rules still allow.