
Dojo
Practical howtos on MikroTik and RouterOS 7: tested configurations, ready-to-copy commands.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Blocking DNS over HTTPS and DNS over TLS with MikroTik
Encrypted DNS bypasses the router's filter: how to block DoT and DoH on RouterOS 7 using port 853, a name-based address list, the tls-host matcher, and Firefox's canary domain, all tested in the lab.
DojoMikroTik in Wi-Fi station and bridge mode: why nothing passes through (and how to fix it)
A MikroTik connected as a client to another access point's Wi-Fi, with a camera behind it: why it doesn't work in station mode, how to fix it with station-pseudobridge, and why the old bridge NAT trick breaks.
DojoTransparent DNS with bridge NAT: the invisible MikroTik that answers for everyone
A bridged MikroTik, invisible to the network, intercepting every DNS request to any server: bridge NAT and IP NAT working together on RouterOS 7, with an example of blocking a website.
DojoThree servers with the same IP on the same LAN: reach them all with MikroTik
Three devices with the same factory address on the same LAN and a PC that needs to talk to all of them: using bridge NAT to answer ARP and IP NAT inside the bridge, on RouterOS 7 you see them as three different addresses, without touching them.
DojoWireGuard VPN from your phone to MikroTik in 5 minutes, with QR code
Your phone joins your home or office network from any Wi-Fi, encrypted. With RouterOS 7, the router automatically generates the keys and phone configuration and displays a QR code to scan with the WireGuard app: interface, firewall, peer, split tunnel, and the precautions you need to know.
DojoMikroTik IP Cloud: a fixed name for the router with a dynamic IP
IP Cloud is MikroTik's free dynamic DNS: it gives the router a fixed name that follows the public address even when it changes. How to enable it, how to verify it, what happens behind the ISP's modem, and why the name alone does not expose the router to the internet.
DojoPort knocking on MikroTik: WinBox opens only for those who knock
The router's management port stays closed to everyone and opens for one hour only to those who touch three ports in the correct sequence. Firewall rules for RouterOS 7, three ways to knock from Linux (knock, nc, and pure bash), and how much you can trust it.
DojoNetwatch on MikroTik: Get Telegram Alerts When a Device Goes Down
Netwatch is the sentinel of RouterOS: it pings an address and, when it stops responding or comes back, runs a script. We use it to monitor a camera and the internet line, with alerts sent to Telegram, and we look at the thresholds and the behavior after a reboot that the manuals do not mention.
DojoConnect MikroTik to Telegram: Router Alerts on Your Phone
A router that messages you on Telegram when something happens is worth more than ten graphs reviewed the next day. In seven steps, we create the bot, find the chat_id, and write a reusable Telegram script. Other Dojo how-tos use it to send alerts: Netwatch, reboots, rogue DHCP.
DojoBasic hardening of a MikroTik router with RouterOS 7
A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.
DojoHotspot and PPPoE MikroTik: the username in every log line
Hotspot connection logs contain IP addresses, not people: to find out who was behind an address, you must cross-reference it with the logins. Using a login and logout script, you can create a log rule for each connected user, with the username in the log-prefix: every log line already contains the name. This works with the hotspot (on-login / on-logout of the user profile) and with PPPoE (on-up / on-down of the PPP profile).
DojoMikroTik Hotspot: How to Log User Traffic
In a hotspot, users access the internet through a single public IP address: to determine who did what, you need a connection log. With RouterOS 7, this is generated using a firewall rule with action=log applied only to new connections, and sent to an external syslog server, because the router's memory is not an archive. Alternatively, or in addition, you can use Traffic Flow (IPFIX/NetFlow) towards a collector.
DojoHotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package
Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.