Skip to content
Dojo

Dojo

Practical howtos on MikroTik and RouterOS 7: tested configurations, ready-to-copy commands.

Illustrazione per Inviare email da MikroTik con Gmail: SMTP e password per le app
Dojo
Howto · System

Send emails from MikroTik with Gmail: SMTP and app passwords

A MikroTik can send emails (alerts, backups, reports) using a Gmail account as the SMTP server: smtp.gmail.com, port 587, STARTTLS. However, the password is not the account password: you need an app password, which Google only issues when two-step verification is enabled. In RouterOS 7, the configuration is located in /tool e-mail.

4 min read
Illustrazione per DHCP server non autorizzato: come scoprirlo e bloccarlo con MikroTikDojo
Howto · DHCP

Unauthorized DHCP server: how to detect and block it with MikroTik

An unauthorized DHCP server, often a mall WiFi router connected "backwards", can bring a LAN to its knees in minutes. With MikroTik, you can detect it using /ip dhcp-server alert, which notifies you when a server other than the valid one responds, and block it using bridge DHCP snooping, which in RouterOS 7 accepts DHCP responses only from trusted ports.

Illustrazione per Scan wireless su un MikroTik remoto senza perdere il risultatoDojo
Howto · WiFi

Wireless scan on a remote MikroTik without losing the result

A frequency scan stops the radio for a few seconds: if you reach the remote router through that wireless link, you lose the connection and the result. The solution is to run the scan in the background on the router itself, saving the result to a file to read once the link is back. In RouterOS 7, this is done with :execute and the file= parameter, which works with both the wifi and wireless packages.

Illustrazione per Come nascondere i router MikroTik della tua rete al tracerouteDojo
Howto · Routing

How to hide your MikroTik routers from traceroute

A traceroute launched by a client shows each router in your network, along with their addresses. By using a mangle rule that increments the TTL (action=change-ttl new-ttl=increment:1), every MikroTik router becomes invisible to traceroute, because the packet passes through it without "consuming" a hop. The rule must be limited to client traffic and applied carefully to avoid complicating troubleshooting.

Illustrazione per CAPsMAN e WiFi RouterOS 7: attivare il client isolationDojo
Howto · WiFi

CAPsMAN and WiFi RouterOS 7: enabling client isolation

Client isolation prevents devices connected to the same WiFi network from communicating with each other: in a hotspot or guest network, it is the first defense against people snooping on others' phones. In RouterOS 7, with the new wifi package and its CAPsMAN, it is enabled with client-isolation=yes in the datapath; with the old wireless package, default-forwarding remains, and in CAPsMAN v1, client-to-client-forwarding.

Illustrazione per Come aggregare più connessioni internet con MikroTik: ECMP e PCC in RouterOS 7Dojo
Howto · Routing

How to aggregate multiple internet connections with MikroTik: ECMP and PCC in RouterOS 7

With a MikroTik, you can use two or more internet connections together. ECMP (multiple default routes with the same distance) is the simplest method but does not let you decide which line a connection uses; PCC (Per Connection Classifier) assigns each connection to a line and keeps it there until the end. In RouterOS 7, PCC uses routing tables (/routing table) and gateway checking with check-gateway. We build it in six steps.

Illustrazione per Come resettare la configurazione di un MikroTik con RouterOS 7Dojo
Howto · System

How to reset a MikroTik configuration with RouterOS 7

To reset a MikroTik from the terminal, use the /system reset-configuration command: with no-defaults=yes, the router boots empty instead of with the factory configuration; with run-after-reset, it runs a script immediately after rebooting. If the router no longer responds, use the reset button or, as a last resort, Netinstall.

Illustrazione per Hotspot MikroTik: come proteggere la LAN dai client WiFiDojo
Howto · Hotspot

MikroTik Hotspot: Protecting the LAN from WiFi Clients

In a MikroTik hotspot, guest clients must not be able to reach the customer's network (servers, printers, NAS). A single firewall rule using the hotspot=from-client matcher is enough; if the network to protect is not known in advance because the WAN gets its address via DHCP, a DHCP client script automatically updates it in an address list.

Illustrazione per DHCP server MikroTik: eseguire uno script a ogni leaseDojo
Howto · DHCP

MikroTik DHCP server: run a script on every lease

The RouterOS DHCP server can run a script every time it assigns or releases an address: this is the lease-script. Inside the script, variables such as $leaseBound, $leaseActIP, and $leaseActMAC are already available, allowing you to log new devices, send email notifications, or add the client to an address list with an expiration.

Illustrazione per Come creare un hotspot WiFi con MikroTik e RouterOS 7Dojo
Howto · Hotspot

How to create a WiFi hotspot with MikroTik and RouterOS 7

A WiFi hotspot with a captive portal on MikroTik is built in seven steps: reset, WAN, guest network on a bridge, radio, /ip hotspot setup wizard, test, and final cleanup. In RouterOS 7, the radio part changes significantly, as recent models use the new wifi package instead of wireless. The addresses in the example are from my lab: adapt them to your network.