Back to blog

MikroTik / Series  ·  13 Parts  ·  ~4.5 hours

MikroTik RouterOS Fundamentals

A complete, practical RouterOS course in 13 writeups — from your first terminal session and the backup that saves your weekend, through VLANs, firewalling, WireGuard, and OSPF, to a full hotel network with guest captive portal and centrally-managed Wi-Fi. Real commands, the gotchas that actually bite, and the same lab-first discipline as our 27-part Cisco series — many posts cross-map between the two platforms.

RouterOS 7 MTCNA → MTCRE Firewall VPN Routing Hospitality

MikroTik gives you enterprise-grade networking at hobbyist prices — and a learning curve shaped like a cliff. This series is the rope: each post takes one capability from "what does this menu do" to "deployed on a paying client's network", in order, with the failure modes we've actually hit across dozens of properties in Crete.

Read it start to finish as a course, or jump to what you need — every post stands alone and links its prerequisites. The series pairs with our Cisco IOS Fundamentals: the concepts are identical, only the syntax changes, and several posts (OSPF, the labs) deliberately bridge both platforms. Planning subnets for any of these builds? Use our subnet & VLAN planner — it exports ready-to-paste RouterOS and Cisco config.

Chapter 1

Foundations

Get comfortable on the box, and make it impossible to lose your work — or your access.

01Terminal TipsThe RouterOS CLI from zero — navigation, print/where queries, Safe Mode, and the habits that prevent lockouts.16 min 02Backup & RecoveryExport vs binary backup — when to use which, automating both, and the full Netinstall recovery procedure.13 min

Chapter 2

The Segmented Network

Split the network into VLANs, publish services safely, and keep the bandwidth fair.

03VLAN SegmentationBridge VLAN filtering done right — trunks, access ports, hardware offload, and isolation you actually test.26 min 04Port Forwardingdst-nat from first principles — publishing services, hairpin NAT, and the checklist for every exposed port.19 min 05QoS for HospitalityQueues that keep guest Wi-Fi fair in high season — PCQ, priorities, and limits that don't punish everyone.18 min

Chapter 3

Automation & Tricks

Make the router do the boring parts itself.

06RouterOS ScriptingVariables, conditions, the scheduler — and the handful of scripts every production router should run.13 min 07Wake-on-LANWake machines through the router — on demand, remotely, and on a schedule.18 min

Chapter 4

Security & VPN

Lock the box and the network down, then connect in from anywhere — properly.

08The RouterOS FirewallConnection tracking, default-deny both chains, FastTrack vs QoS, and self-updating brute-force traps.21 min 09WireGuard VPNRoad-warrior and site-to-site — the allowed-address logic demystified, and keepalive for peers behind NAT.20 min

Chapter 5

Routing & the Lab

Dynamic routing on the new engine, then everything assembled into one real build.

10OSPF on RouterOS 7 — and Talking to CiscoInstance, area, interface-template — proven on a mixed topology where one neighbor is a Cisco 2911.21 min 11Lab: The Hotel Network, Start to FinishRB5009 + CRS326 + tagged SSIDs — guest isolation with evidence, PCQ fairness, and failure drills before handover.24 min

Chapter 6

Guest Access & Wireless

The guest-facing front door, then scale the Wi-Fi from two APs to a managed fleet.

12Hotspot & Captive Portal for HotelsA branded guest login — terms acceptance, vouchers with User Manager, RADIUS, walled garden, per-guest bandwidth, and the HTTPS reality.22 min 13Centralised Wi-Fi with CAPsMANRouterOS 7 WifiWave2 — one config for every AP, VLAN-tagged SSIDs, seamless roaming, and the CAP discovery gotchas.21 min

Want this network without reading all 13?

NOCTIS designs, secures, and operates MikroTik and Cisco networks for hotels, villas, and SMBs across Crete — segmentation with evidence, fair guest Wi-Fi, and failover we test by pulling cables. The whole series, applied to your building.

Book a Discovery Call →