Satura centrs

MikroTik blogs un operatīvas piezīmes

Rokasgrāmatas, WinBox, LTE un firmware stratēģijas.

security1.06.2026. 12 min

Network segmentation: isolating CCTV from the office LAN on MikroTik

A flat network where IP cameras share a broadcast domain with office PCs is a liability: one compromised camera can reach file shares, and multicast noise drags everyone down. Here is how to split cameras, office and management into VLANs on MikroTik, with a default-deny inter-VLAN firewall that only lets the NVR reach the cameras.

securityvlancctvsegmentationfirewallnis2
security25.05.2026. 12 min

Hardening RouterOS: 10 things to do right after unboxing

A factory-default RouterOS box on a public IP is found and probed within minutes. Here are ten concrete steps to take before it goes live: change the winbox port, lock down /ip service, replace the admin user, fence off neighbor discovery and the MAC-server, set an input firewall, and back up — without locking yourself out.

securityhardeningrouterosfirewallwinboxromon
wifi18.05.2026. 11 min

Wi-Fi roaming and sticky clients: 802.11r/k/v on RouterOS and why the client decides

A laptop sitting two rooms away still clings to the first AP it joined at -80 dBm while a near AP idles. Here is what 802.11r, 802.11k and 802.11v actually do, why the client (not the AP) chooses to roam, and how to nudge it with access-list and signal-range on RouterOS.

wifiroaming802-11r802-11k802-11vcapsmanaccess-list
cctv7.05.2026. 9 min

PoE Power Budgeting: Classes, Voltage Drop and Not Browning Out at Dusk

Per-port PoE class is the easy number; the switch's total budget and voltage drop over 90 metres of Cat5e are where installs actually fail. Here is how to size so every IR illuminator can kick in at dusk without browning out the rack.

cctvpoepower-budgetvoltage-drop802-3btcablingswitching
wifi4.05.2026. 9 min

2.4 vs 5 vs 6 GHz on an industrial site: choosing bands for warehouses and factories

Industrial RF is hostile: metal racking, concrete, machinery, and electrical noise wreck assumptions that hold in an office. Each band trades range against capacity and cleanliness — 2.4 GHz reaches but is crowded and narrow, 5 GHz has room but shorter reach and DFS surprises, 6 GHz adds clean spectrum where you have it. The gotcha: wide 80 MHz channels often underperform 20/40 MHz in a noisy plant.

2-4-ghz5-ghz6-ghzchannel-planningindustrialdfschannel-width
cctv30.04.2026. 10 min

Designing a Network for 150+ Cameras: VLANs, Multicast and Oversubscription

A flat /24 with 150 cameras and the office on the same broadcast domain is a fire waiting to start. Here is how to layer access/aggregation/core, segment with VLANs, and do the oversubscription math so the NVR never starves.

cctvnetwork-designvlanigmp-snoopingmulticastswitchingnvr
vpn16.04.2026. 8 min

Reaching Devices Behind CGNAT: The Outbound Tunnel Pattern

On most LTE and mobile operators your router never gets a real public IP — it sits behind carrier-grade NAT, so port-forwarding and DDNS simply cannot work. Here is how to confirm CGNAT and the one pattern that fixes it: an outbound WireGuard tunnel to a VPS.

cgnatwireguardltepersistent-keepalivevpsnat-traversal
vpn9.04.2026. 9 min

L2TP/IPsec vs WireGuard vs OpenVPN Over a Weak LTE Link

Over a flaky LTE link the VPN protocol you pick decides whether the tunnel survives the connection dropping and the IP changing. A field-tested comparison of overhead, MTU pain, NAT traversal, CPU cost and reconnection behavior.

wireguardl2tp-ipsecopenvpnltemtumss-clamp
wifi6.04.2026. 9 min

Wireless PtP and PtMP for video backhaul: when it works and when it doesn't

Wireless can carry camera video reliably — but only when the RF reality cooperates. Line-of-sight and a clear Fresnel zone are non-negotiable, throughput falls with distance and noise, and PtMP needs TDMA to survive hidden nodes. Size for aggregate camera bitrate plus headroom, and remember that the link that worked in March may die when the leaves come out.

ptpptmpvideo-backhaulnv2fresnel-zoneline-of-sightwireless
vpn26.03.2026. 9 min

A WireGuard hub on a VPS for 150 sites: addressing, routing and scale

One tunnel to one NVR is easy. A hundred and fifty sites is an architecture problem: a VPS hub, a clean IP plan, every spoke dialing out so CGNAT never matters, and the discipline to keep 150 peer configs from becoming a swamp.

wireguardvpshub-and-spokecgnatip-addressingrouterosscaling
security21.03.2026. 15 min

Kā mikroHUB atbilst ISO 27001, NIS2 un SOC 2 prasībām

Padziļināts skatījums uz drošības kontrolēm, šifrēšanas standartiem un atbilstības pasākumiem, kas padara mikroHUB gatavu uzņēmuma izvietojumiem regulētos vidēs.

complianceiso-27001nis2soc-2securitygdpr
firmware19.03.2026. 10 min

Izvēle starp stable, long-term, testing un development

Konkrēta politika MikroTik izlaižu kanālu kartēšanai uz ražošanu, malu, laboratoriju un pirmsizlaižu vidi — ar reālām komandām un pieredzētu operatīvu padomu.

stablelong-termtestingdevelopment
security19.03.2026. 14 min

Zero-trust pārvaldes modeļi MikroTik flotēm

Kā novērst ienākošās pārvaldes portus, ierobežot pakalpojumu piekļuvi, rotēt akreditācijas un būvēt slāņotu firewall aizsardzību RouterOS mērogā.

securityzero-trustwireguard
vpn19.03.2026. 8 min

WireGuard on RouterOS to reach an NVR behind a site with no public IP

The NVR is at a site on CGNAT and you need to see the cameras from your laptop. WireGuard on RouterOS does it cleanly — but only if you understand that allowed-address is two things at once and that the return route is the part everyone forgets.

wireguardrouteroscctvnvrremote-accessvpnnat-traversal
wifi16.03.2026. 9 min

CAPsMAN: centrally managing MikroTik access points across distributed sites

When you run more than a handful of MikroTik APs across several buildings, configuring each one by hand stops scaling. CAPsMAN gives you one controller, one config, and provisioning rules that auto-set up new APs as they appear. The catch is datapath forwarding — get local vs manager forwarding wrong and you bottleneck a whole site.

capsmanwifimikrotikrouteroswifiwave2central-managementprovisioning
operations12.03.2026. 9 min

Upgrading firmware on 150 MikroTik devices without driving to each site

A remote firmware upgrade across a real fleet is not one button. You juggle two separate things RouterOS calls firmware, choose and freeze an update channel, roll out in waves, and keep a way back when a device strands itself on the far end of a tunnel.

routerosfirmwarefleet-managementoperationsupgraderollbackrouterboard
compare26.02.2026. 11 min

The Dude in 2026: still great, but where it shows its age

An honest look at what The Dude still does brilliantly, where a single-host design hurts you across many remote sites, and what modern cloud monitoring buys you — along with the tradeoffs you actually pay.

the-dudemonitoringmikrotikcloud-monitoringcomparisonmulti-sitesnmp
switching23.02.2026. 11 min

Switch hygiene on a live site: storm-control, port isolation and MAC limits

Three features that contain the blast radius when someone plugs the wrong thing into the wrong port: storm-control caps broadcast floods, bridge horizon isolates client ports, and MAC learning limits stop rogue devices. Concrete RouterOS bridge config and the horizon gotcha.

storm-controlport-isolationbridge-horizonmac-filteringbridgemikrotikswitching
operations19.02.2026. 11 min

Onboarding 100+ MikroTik routers without configuring each one by hand

How to build a single-line, idempotent .rsc template you can paste into any RouterOS terminal, parameterize per site, and re-run safely — so a fleet rollout stops being a hundred individual jobs.

routerosprovisioningautomationrsc-scriptonboardingfleetidempotent
operations12.02.2026. 10 min

Binary backup vs /export (.rsc): the recovery strategy you actually need

A binary /system backup and an /export .rsc are not two ways to do the same thing — they fail and shine in opposite situations. One is a fast same-box snapshot with secrets baked in; the other is a portable, diff-able, partially-restorable text file. Keep both, and know exactly what each one silently leaves out.

backupexportrscrecoveryprovisioningversion-control
operations5.02.2026. 10 min

Netinstall step by step: rescuing a bricked or locked-out RouterBOARD

When a RouterBOARD forgets its password, dies mid-upgrade, or sits in a boot loop, Netinstall is the tool that reliably brings it back. The catches are physical and network-level: a direct Layer-2 link, etherboot mode, no competing DHCP, the right architecture package, and a Windows firewall that loves to eat the BOOTP handshake.

netinstallrouterboardrecoverybootpetherbootoperations
security29.01.2026. 11 min

A solid base firewall for MikroTik: order, raw, and connection-state

Most MikroTik firewalls fall apart because the rules are in the wrong order, not because a rule is missing. Here is a field-tested base: how first-match ordering works, why raw runs before connection tracking, the established/related/invalid/new logic, separating input from forward, the fasttrack tradeoff, and how not to lock yourself out.

firewallrouterossecurityconnection-trackingfasttrackraw
operations15.01.2026. 11 min

RouterOS 6 to 7: what actually changed for someone who runs these boxes

A practitioner's honest accounting of the v6-to-v7 jump: new kernel, built-in WireGuard, a rebuilt routing engine, ROSE storage and containers — and the migration surprises that bite when you upgrade a live edge router.

routerosrouteros7upgradewireguardroutingcontainersoperations
switching12.01.2026. 11 min

QoS for video: protecting live view and recordings on a shared link

Video traffic suffers from jitter and loss long before it runs out of bandwidth. Marking with DSCP, queuing with simple queues or a queue tree, and taming bufferbloat at the one congestion point you actually control.

qosdscpqueue-treebufferbloatnvrrtspmikrotik
networking9.01.2026. 10 min

VLANs on RouterOS 7 the right way: bridge VLAN filtering, not the old multi-bridge mess

The modern bridge VLAN filtering model replaces the tangle of multiple bridges and VLAN interfaces most installers still copy from old forum posts. Here is how tagged/untagged ports, PVID and the bridge VLAN table actually fit together — plus the one mistake that silently breaks your management access.

vlanrouterosbridgevlan-filteringswitchinghardware-offloadnetworking