مرکز محتوا

وبلاگ و یادداشت‌های عملیاتی میکروتیک

راهنماها، WinBox، LTE و استراتژی فریم‌ور.

security۱۴۰۵/۳/۱۱ 12 دقیقه

Network segmentation: isolating CCTV from the office LAN on MikroTik

A flat network where IP cameras share a broadcast domain with office PCs is a liability: one compromised camera can reach file shares, and multicast noise drags everyone down. Here is how to split cameras, office and management into VLANs on MikroTik, with a default-deny inter-VLAN firewall that only lets the NVR reach the cameras.

securityvlancctvsegmentationfirewallnis2
switching۱۴۰۵/۳/۷ 9 دقیقه

Managed vs unmanaged switch in a CCTV install: when cheap is fine and when it costs you a truck roll

An unmanaged switch is genuinely fine on small flat jobs and a liability on anything that needs VLANs, PoE control, loop protection, IGMP snooping or remote diagnosis. Here is the honest line between the two, the MikroTik options, and why the cheap switch becomes a blind spot you cannot fix from your desk.

managed-switchunmanaged-switchvlanpoeigmp-snoopingcctvswos
security۱۴۰۵/۳/۴ 12 دقیقه

Hardening RouterOS: 10 things to do right after unboxing

A factory-default RouterOS box on a public IP is found and probed within minutes. Here are ten concrete steps to take before it goes live: change the winbox port, lock down /ip service, replace the admin user, fence off neighbor discovery and the MAC-server, set an input firewall, and back up — without locking yourself out.

securityhardeningrouterosfirewallwinboxromon
lte۱۴۰۵/۲/۳۱ 10 دقیقه

LTE as backup or primary for remote sites: failover, failback, and not blowing the data plan

Designing LTE failover on RouterOS that actually works: route distance, check-gateway, netwatch scripts, recursive routing for reliable detection, automatic failback with hysteresis, and the metered-data discipline that keeps an LTE link from becoming a billing surprise.

ltefailovercheck-gatewaynetwatchrecursive-routingcgnatremote-sites
wifi۱۴۰۵/۲/۲۸ 11 دقیقه

Wi-Fi roaming and sticky clients: 802.11r/k/v on RouterOS and why the client decides

A laptop sitting two rooms away still clings to the first AP it joined at -80 dBm while a near AP idles. Here is what 802.11r, 802.11k and 802.11v actually do, why the client (not the AP) chooses to roam, and how to nudge it with access-list and signal-range on RouterOS.

wifiroaming802-11r802-11k802-11vcapsmanaccess-list
cctv۱۴۰۵/۲/۱۷ 9 دقیقه

PoE Power Budgeting: Classes, Voltage Drop and Not Browning Out at Dusk

Per-port PoE class is the easy number; the switch's total budget and voltage drop over 90 metres of Cat5e are where installs actually fail. Here is how to size so every IR illuminator can kick in at dusk without browning out the rack.

cctvpoepower-budgetvoltage-drop802-3btcablingswitching
wifi۱۴۰۵/۲/۱۴ 9 دقیقه

2.4 vs 5 vs 6 GHz on an industrial site: choosing bands for warehouses and factories

Industrial RF is hostile: metal racking, concrete, machinery, and electrical noise wreck assumptions that hold in an office. Each band trades range against capacity and cleanliness — 2.4 GHz reaches but is crowded and narrow, 5 GHz has room but shorter reach and DFS surprises, 6 GHz adds clean spectrum where you have it. The gotcha: wide 80 MHz channels often underperform 20/40 MHz in a noisy plant.

2-4-ghz5-ghz6-ghzchannel-planningindustrialdfschannel-width
cctv۱۴۰۵/۲/۱۰ 10 دقیقه

Designing a Network for 150+ Cameras: VLANs, Multicast and Oversubscription

A flat /24 with 150 cameras and the office on the same broadcast domain is a fire waiting to start. Here is how to layer access/aggregation/core, segment with VLANs, and do the oversubscription math so the NVR never starves.

cctvnetwork-designvlanigmp-snoopingmulticastswitchingnvr
cctv۱۴۰۵/۲/۳ 9 دقیقه

How Much Bandwidth Does an IP Camera Really Use? H.264 vs H.265, CBR vs VBR

Camera datasheets quote a tidy bitrate; real installations don't behave that tidily. Here is how bitrate actually scales with resolution, frame rate, codec and scene motion, and how to sum N cameras into an uplink you won't regret.

cctvip-camerabandwidthh265h264vbrnetwork-design
vpn۱۴۰۵/۱/۲۷ 8 دقیقه

Reaching Devices Behind CGNAT: The Outbound Tunnel Pattern

On most LTE and mobile operators your router never gets a real public IP — it sits behind carrier-grade NAT, so port-forwarding and DDNS simply cannot work. Here is how to confirm CGNAT and the one pattern that fixes it: an outbound WireGuard tunnel to a VPS.

cgnatwireguardltepersistent-keepalivevpsnat-traversal
vpn۱۴۰۵/۱/۲۰ 9 دقیقه

L2TP/IPsec vs WireGuard vs OpenVPN Over a Weak LTE Link

Over a flaky LTE link the VPN protocol you pick decides whether the tunnel survives the connection dropping and the IP changing. A field-tested comparison of overhead, MTU pain, NAT traversal, CPU cost and reconnection behavior.

wireguardl2tp-ipsecopenvpnltemtumss-clamp
wifi۱۴۰۵/۱/۱۷ 9 دقیقه

Wireless PtP and PtMP for video backhaul: when it works and when it doesn't

Wireless can carry camera video reliably — but only when the RF reality cooperates. Line-of-sight and a clear Fresnel zone are non-negotiable, throughput falls with distance and noise, and PtMP needs TDMA to survive hidden nodes. Size for aggregate camera bitrate plus headroom, and remember that the link that worked in March may die when the leaves come out.

ptpptmpvideo-backhaulnv2fresnel-zoneline-of-sightwireless
vpn۱۴۰۵/۱/۶ 9 دقیقه

A WireGuard hub on a VPS for 150 sites: addressing, routing and scale

One tunnel to one NVR is easy. A hundred and fifty sites is an architecture problem: a VPS hub, a clean IP plan, every spoke dialing out so CGNAT never matters, and the discipline to keep 150 peer configs from becoming a swamp.

wireguardvpshub-and-spokecgnatip-addressingrouterosscaling
lte۱۴۰۴/۱۲/۲۸ 11 دقیقه

تشخیص MikroTik LTE: خواندن صحیح RSRP، RSRQ و SINR

قدرت سیگنال کافی نیست. با نحوه خواندن معیارهای کیفیت LTE با آستانه های واقعی، دستورات RouterOS، تکنیک های قفل باند و منطق عیب یابی سیستماتیک آشنا شوید.

ltersrprsrqsinr
firmware۱۴۰۴/۱۲/۲۸ 10 دقیقه

انتخاب بین پایدار، بلند مدت، آزمایش و توسعه

یک خط مشی مشخص برای نگاشت کانال های انتشار MikroTik به محیط های تولید، لبه، آزمایشگاه و محیط های پیش از انتشار - با دستورات واقعی و توصیه های عملیاتی که به سختی به دست آمده اند.

stablelong-termtestingdevelopment
vpn۱۴۰۴/۱۲/۲۸ 8 دقیقه

WireGuard on RouterOS to reach an NVR behind a site with no public IP

The NVR is at a site on CGNAT and you need to see the cameras from your laptop. WireGuard on RouterOS does it cleanly — but only if you understand that allowed-address is two things at once and that the return route is the part everyone forgets.

wireguardrouteroscctvnvrremote-accessvpnnat-traversal
wifi۱۴۰۴/۱۲/۲۵ 9 دقیقه

CAPsMAN: centrally managing MikroTik access points across distributed sites

When you run more than a handful of MikroTik APs across several buildings, configuring each one by hand stops scaling. CAPsMAN gives you one controller, one config, and provisioning rules that auto-set up new APs as they appear. The catch is datapath forwarding — get local vs manager forwarding wrong and you bottleneck a whole site.

capsmanwifimikrotikrouteroswifiwave2central-managementprovisioning
operations۱۴۰۴/۱۲/۲۱ 9 دقیقه

Upgrading firmware on 150 MikroTik devices without driving to each site

A remote firmware upgrade across a real fleet is not one button. You juggle two separate things RouterOS calls firmware, choose and freeze an update channel, roll out in waves, and keep a way back when a device strands itself on the far end of a tunnel.

routerosfirmwarefleet-managementoperationsupgraderollbackrouterboard
operations۱۴۰۴/۱۲/۱۴ 11 دقیقه

Monitoring availability across many distributed sites without drowning in alerts

What to actually alert on across dozens of remote MikroTik sites, how to set thresholds that survive flaky LTE, how to tier escalation, and how to reach the on-call person without training everyone to ignore the alarms.

monitoringalertingmulti-sitelteon-callalert-fatigueescalation
compare۱۴۰۴/۱۲/۷ 11 دقیقه

The Dude in 2026: still great, but where it shows its age

An honest look at what The Dude still does brilliantly, where a single-host design hurts you across many remote sites, and what modern cloud monitoring buys you — along with the tradeoffs you actually pay.

the-dudemonitoringmikrotikcloud-monitoringcomparisonmulti-sitesnmp
switching۱۴۰۴/۱۲/۴ 11 دقیقه

Switch hygiene on a live site: storm-control, port isolation and MAC limits

Three features that contain the blast radius when someone plugs the wrong thing into the wrong port: storm-control caps broadcast floods, bridge horizon isolates client ports, and MAC learning limits stop rogue devices. Concrete RouterOS bridge config and the horizon gotcha.

storm-controlport-isolationbridge-horizonmac-filteringbridgemikrotikswitching
operations۱۴۰۴/۱۱/۳۰ 11 دقیقه

Onboarding 100+ MikroTik routers without configuring each one by hand

How to build a single-line, idempotent .rsc template you can paste into any RouterOS terminal, parameterize per site, and re-run safely — so a fleet rollout stops being a hundred individual jobs.

routerosprovisioningautomationrsc-scriptonboardingfleetidempotent
operations۱۴۰۴/۱۱/۲۳ 10 دقیقه

Binary backup vs /export (.rsc): the recovery strategy you actually need

A binary /system backup and an /export .rsc are not two ways to do the same thing — they fail and shine in opposite situations. One is a fast same-box snapshot with secrets baked in; the other is a portable, diff-able, partially-restorable text file. Keep both, and know exactly what each one silently leaves out.

backupexportrscrecoveryprovisioningversion-control
operations۱۴۰۴/۱۱/۱۶ 10 دقیقه

Netinstall step by step: rescuing a bricked or locked-out RouterBOARD

When a RouterBOARD forgets its password, dies mid-upgrade, or sits in a boot loop, Netinstall is the tool that reliably brings it back. The catches are physical and network-level: a direct Layer-2 link, etherboot mode, no competing DHCP, the right architecture package, and a Windows firewall that loves to eat the BOOTP handshake.

netinstallrouterboardrecoverybootpetherbootoperations
switching۱۴۰۴/۱۱/۱۳ 12 دقیقه

SFP, SFP+, fiber and DAC in real installs: optics that actually link up

1G SFP versus 10G SFP+, multimode versus single-mode, when DAC beats fiber for a rack hop, vendor coding tolerance on MikroTik, reading optical power with DDM, and the BiDi wavelength mismatch that silently kills a link.

sfpsfp-plusfiberdacddmsingle-modebidi
security۱۴۰۴/۱۱/۹ 11 دقیقه

A solid base firewall for MikroTik: order, raw, and connection-state

Most MikroTik firewalls fall apart because the rules are in the wrong order, not because a rule is missing. Here is a field-tested base: how first-match ordering works, why raw runs before connection tracking, the established/related/invalid/new logic, separating input from forward, the fasttrack tradeoff, and how not to lock yourself out.

firewallrouterossecurityconnection-trackingfasttrackraw
operations۱۴۰۴/۱۰/۲۵ 11 دقیقه

RouterOS 6 to 7: what actually changed for someone who runs these boxes

A practitioner's honest accounting of the v6-to-v7 jump: new kernel, built-in WireGuard, a rebuilt routing engine, ROSE storage and containers — and the migration surprises that bite when you upgrade a live edge router.

routerosrouteros7upgradewireguardroutingcontainersoperations
switching۱۴۰۴/۱۰/۲۲ 11 دقیقه

QoS for video: protecting live view and recordings on a shared link

Video traffic suffers from jitter and loss long before it runs out of bandwidth. Marking with DSCP, queuing with simple queues or a queue tree, and taming bufferbloat at the one congestion point you actually control.

qosdscpqueue-treebufferbloatnvrrtspmikrotik
networking۱۴۰۴/۱۰/۱۹ 10 دقیقه

VLANs on RouterOS 7 the right way: bridge VLAN filtering, not the old multi-bridge mess

The modern bridge VLAN filtering model replaces the tangle of multiple bridges and VLAN interfaces most installers still copy from old forum posts. Here is how tagged/untagged ports, PVID and the bridge VLAN table actually fit together — plus the one mistake that silently breaks your management access.

vlanrouterosbridgevlan-filteringswitchinghardware-offloadnetworking