A complete, practical RouterOS course in 13 writeups — from your first terminal session and the backup that saves your weekend, through VLANs, firewalling, WireGuard, and OSPF, to a full hotel network with guest captive portal and centrally-managed Wi-Fi. Real commands, the gotchas that actually bite, and the same lab-first discipline as our 27-part Cisco series — many posts cross-map between the two platforms.
MikroTik gives you enterprise-grade networking at hobbyist prices — and a learning curve shaped like a cliff. This series is the rope: each post takes one capability from "what does this menu do" to "deployed on a paying client's network", in order, with the failure modes we've actually hit across dozens of properties in Crete.
Read it start to finish as a course, or jump to what you need — every post stands alone and links its prerequisites. The series pairs with our Cisco IOS Fundamentals: the concepts are identical, only the syntax changes, and several posts (OSPF, the labs) deliberately bridge both platforms. Planning subnets for any of these builds? Use our subnet & VLAN planner — it exports ready-to-paste RouterOS and Cisco config.
Chapter 1
Get comfortable on the box, and make it impossible to lose your work — or your access.
01Terminal TipsThe RouterOS CLI from zero — navigation, print/where queries, Safe Mode, and the habits that prevent lockouts.16 min→ 02Backup & RecoveryExport vs binary backup — when to use which, automating both, and the full Netinstall recovery procedure.13 min→Chapter 2
Split the network into VLANs, publish services safely, and keep the bandwidth fair.
03VLAN SegmentationBridge VLAN filtering done right — trunks, access ports, hardware offload, and isolation you actually test.26 min→ 04Port Forwardingdst-nat from first principles — publishing services, hairpin NAT, and the checklist for every exposed port.19 min→ 05QoS for HospitalityQueues that keep guest Wi-Fi fair in high season — PCQ, priorities, and limits that don't punish everyone.18 min→Chapter 3
Make the router do the boring parts itself.
06RouterOS ScriptingVariables, conditions, the scheduler — and the handful of scripts every production router should run.13 min→ 07Wake-on-LANWake machines through the router — on demand, remotely, and on a schedule.18 min→Chapter 4
Lock the box and the network down, then connect in from anywhere — properly.
08The RouterOS FirewallConnection tracking, default-deny both chains, FastTrack vs QoS, and self-updating brute-force traps.21 min→ 09WireGuard VPNRoad-warrior and site-to-site — the allowed-address logic demystified, and keepalive for peers behind NAT.20 min→Chapter 5
Dynamic routing on the new engine, then everything assembled into one real build.
10OSPF on RouterOS 7 — and Talking to CiscoInstance, area, interface-template — proven on a mixed topology where one neighbor is a Cisco 2911.21 min→ 11Lab: The Hotel Network, Start to FinishRB5009 + CRS326 + tagged SSIDs — guest isolation with evidence, PCQ fairness, and failure drills before handover.24 min→Chapter 6
The guest-facing front door, then scale the Wi-Fi from two APs to a managed fleet.
12Hotspot & Captive Portal for HotelsA branded guest login — terms acceptance, vouchers with User Manager, RADIUS, walled garden, per-guest bandwidth, and the HTTPS reality.22 min→ 13Centralised Wi-Fi with CAPsMANRouterOS 7 WifiWave2 — one config for every AP, VLAN-tagged SSIDs, seamless roaming, and the CAP discovery gotchas.21 min→NOCTIS designs, secures, and operates MikroTik and Cisco networks for hotels, villas, and SMBs across Crete — segmentation with evidence, fair guest Wi-Fi, and failover we test by pulling cables. The whole series, applied to your building.
Book a Discovery Call →