Back To Home
Back To Home enables secure VPN access from anywhere to your router, even if it lacks a public IP or is behind NAT. It uses MikroTik relay servers for indirect connections, ensuring end-to-end encryption without exposing keys. The feature supports both smartphone apps and manual RouterOS configuration, including sharing tunnels with guests or via WireGuard for computers.
CHR: Hetzner Cloud Installation
This page provides an overview for deploying MikroTik RouterOS Cloud Hosted Router (CHR) on Hetzner Cloud, detailing the installation process including server creation, rescue system activation, CHR image deployment via SSH, and reboot instructions while emphasizing security best practices.
IKEv2 EAP between NordVPN and RouterOS
This page guides users through configuring an IKEv2 secured tunnel to NordVPN servers using EAP authentication in RouterOS v6.45+, covering root CA installation, server hostname lookup, IPsec tunnel setup with Phase 1/2 profiles and policies, mode configuration for EAP authentication, and peer/identity credential setup.
PPTP
This page documents the PPTP (Point-to-Point Tunneling Protocol) implementation in MikroTik RouterOS, covering client and server configuration options including authentication methods, MTU/MRRU settings, and TCP port requirements. It highlights security limitations and provides example setup commands for PPTP client connections.
RADIUS
RADIUS enables centralized authentication and accounting for PPP, HotSpot, and other services in MikroTik RouterOS by connecting to a RADIUS server via UDP or RadSec protocol, with configurable ports, shared secrets, and service-specific settings.
Securing your router
This page provides security recommendations for MikroTik RouterOS, including upgrading RouterOS versions, changing default usernames and passwords, securing access with firewall rules and VPNs, disabling unnecessary services like MAC-Telnet and Neighbor Discovery, and managing DNS caching to enhance router security.
Software Specifications
This page outlines RouterOS software specifications covering hardware compatibility, installation methods, configuration tools, backup/restore capabilities, firewall features, routing protocols, and MPLS support for MikroTik devices.
SSTP
SSTP provides secure remote access over HTTPS using TLS encryption, enabling VPN connections through firewalls and NAT devices. The page details SSTP client and server properties including authentication, encryption settings, and connection management options for MikroTik RouterOS.
Virtual Private Networks
VPN documentation provides comprehensive guides for configuring secure and encapsulated connectivity using RouterOS tunnel technologies such as IPsec, L2TP, PPTP, OpenVPN, WireGuard, and others.
WireGuard
WireGuard is a modern VPN solution offering fast, secure encryption across platforms with detailed configuration options including private/public keys, VRF routing, and peer management for establishing encrypted tunnels between devices.