Skip to content
Dojo

Dojo

Practical howtos on MikroTik and RouterOS 7: tested configurations, ready-to-copy commands.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per Bloccare DNS over HTTPS e DNS over TLS con MikroTik
Dojo

Blocking DNS over HTTPS and DNS over TLS with MikroTik

Encrypted DNS bypasses the router's filter: how to block DoT and DoH on RouterOS 7 using port 853, a name-based address list, the tls-host matcher, and Firefox's canary domain, all tested in the lab.

7 min read
Illustrazione per MikroTik in Wi-Fi station e bridge: perché dietro non passa niente (e come si risolve)Dojo

MikroTik in Wi-Fi station and bridge mode: why nothing passes through (and how to fix it)

A MikroTik connected as a client to another access point's Wi-Fi, with a camera behind it: why it doesn't work in station mode, how to fix it with station-pseudobridge, and why the old bridge NAT trick breaks.

Illustrazione per DNS trasparente con il bridge NAT: il MikroTik invisibile che risponde a tuttiDojo

Transparent DNS with bridge NAT: the invisible MikroTik that answers for everyone

A bridged MikroTik, invisible to the network, intercepting every DNS request to any server: bridge NAT and IP NAT working together on RouterOS 7, with an example of blocking a website.

Illustrazione per Tre server con lo stesso IP: raggiungerli tutti con MikroTikDojo

Three servers with the same IP on the same LAN: reach them all with MikroTik

Three devices with the same factory address on the same LAN and a PC that needs to talk to all of them: using bridge NAT to answer ARP and IP NAT inside the bridge, on RouterOS 7 you see them as three different addresses, without touching them.

Illustrazione per VPN WireGuard dal telefono al MikroTik in 5 minuti, con il QR codeDojo

WireGuard VPN from your phone to MikroTik in 5 minutes, with QR code

Your phone joins your home or office network from any Wi-Fi, encrypted. With RouterOS 7, the router automatically generates the keys and phone configuration and displays a QR code to scan with the WireGuard app: interface, firewall, peer, split tunnel, and the precautions you need to know.

Illustrazione per IP Cloud MikroTik: un nome fisso per il router con l'IP dinamicoDojo

MikroTik IP Cloud: a fixed name for the router with a dynamic IP

IP Cloud is MikroTik's free dynamic DNS: it gives the router a fixed name that follows the public address even when it changes. How to enable it, how to verify it, what happens behind the ISP's modem, and why the name alone does not expose the router to the internet.

Illustrazione per Port knocking su MikroTik: WinBox si apre solo a chi bussaDojo

Port knocking on MikroTik: WinBox opens only for those who knock

The router's management port stays closed to everyone and opens for one hour only to those who touch three ports in the correct sequence. Firewall rules for RouterOS 7, three ways to knock from Linux (knock, nc, and pure bash), and how much you can trust it.

Illustrazione per Netwatch su MikroTik: avvisami su Telegram quando un apparato cadeDojo

Netwatch on MikroTik: Get Telegram Alerts When a Device Goes Down

Netwatch is the sentinel of RouterOS: it pings an address and, when it stops responding or comes back, runs a script. We use it to monitor a camera and the internet line, with alerts sent to Telegram, and we look at the thresholds and the behavior after a reboot that the manuals do not mention.

Illustrazione per Collegare MikroTik a Telegram: gli avvisi del router sul telefonoDojo

Connect MikroTik to Telegram: Router Alerts on Your Phone

A router that messages you on Telegram when something happens is worth more than ten graphs reviewed the next day. In seven steps, we create the bot, find the chat_id, and write a reusable Telegram script. Other Dojo how-tos use it to send alerts: Netwatch, reboots, rogue DHCP.

Illustrazione per Hardening di base di un router MikroTik con RouterOS 7Dojo
Howto · Security

Basic hardening of a MikroTik router with RouterOS 7

A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.

Illustrazione per Hotspot e PPPoE MikroTik: il nome utente in ogni riga di logDojo
Howto · Hotspot

Hotspot and PPPoE MikroTik: the username in every log line

Hotspot connection logs contain IP addresses, not people: to find out who was behind an address, you must cross-reference it with the logins. Using a login and logout script, you can create a log rule for each connected user, with the username in the log-prefix: every log line already contains the name. This works with the hotspot (on-login / on-logout of the user profile) and with PPPoE (on-up / on-down of the PPP profile).

Illustrazione per Hotspot MikroTik: come registrare il traffico degli utentiDojo
Howto · Hotspot

MikroTik Hotspot: How to Log User Traffic

In a hotspot, users access the internet through a single public IP address: to determine who did what, you need a connection log. With RouterOS 7, this is generated using a firewall rule with action=log applied only to new connections, and sent to an external syslog server, because the router's memory is not an archive. Alternatively, or in addition, you can use Traffic Flow (IPFIX/NetFlow) towards a collector.

Illustrazione per Hotspot 2.0 e Passpoint con MikroTik: l'interworking nel pacchetto wifiDojo
Howto · WiFi

Hotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package

Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.