The technical terms we use in the Dojo’s how-to guides and articles, explained in a few lines. In the articles, they are underlined with a dashed line: hover over them (or tap them on a phone) to read the definition on the fly.

#
802.11u
The IEEE standard that allows an access point to describe its network (operator, services, accepted credentials) before the device connects. It is the foundation of Hotspot 2.0 and Passpoint.
A
Address list
A named list of IP addresses used by RouterOS firewall rules. It can be updated without modifying the rules, and entries can have an expiration time (timeout).
B
Back To Home
MikroTik's ready-to-use WireGuard VPN: it is enabled from IP Cloud and, when the router is not directly reachable (for example, behind CGNAT), it goes through a MikroTik relay.
Back To Home Relay
The intermediate MikroTik server that Back To Home traffic passes through when the router cannot be reached directly. The traffic remains end-to-end encrypted: the relay does not read it.
Backup
In RouterOS, a .backup file is a complete binary copy of the configuration, including passwords, intended for restoration on the same model. To read or reuse the configuration, use an export instead.
Bogon
An address that should never arrive from the internet: private, loopback, or reserved. If it comes from the WAN, it is spoofed or the result of an error, and it is discarded.
Bridge
A virtual interface that combines multiple ports (Ethernet, WiFi, VLAN) into the same network segment, like a switch. In RouterOS, LAN IP addresses and services are usually placed on the bridge.
Broadcast
The last address of an IPv4 subnet, used to address all devices on the network simultaneously. It is not assigned to a device. By extension, traffic sent to all devices (ARP, DHCP).
Brute force
An attack that tries thousands of username and password combinations until one works. It is countered with non-obvious usernames, long passwords, and services not exposed to the internet.
C
CAPsMAN
The centralized controller for MikroTik access points: configure all APs (CAPs) on the network from a single router. In RouterOS 7, it is available in both the wireless package and the new wifi package.
Captive portal
The login page that users connecting to a hotspot are redirected to: they cannot browse until they authenticate.
CGNAT
The NAT performed by the operator: multiple customers exit to the internet using the same public IP address, and no port can be forwarded from outside to your router.
Chain
Each group of firewall rules. In RouterOS, the main ones are input (traffic destined for the router), forward (traffic passing through the router), and output (traffic generated by the router).
check-gateway
A route option that makes RouterOS check every 10 seconds whether the gateway responds: if it does not respond, the route is disabled and traffic is switched to the backup routes.
CHR
Cloud Hosted Router: RouterOS in virtual machine form, to be run on a hypervisor or in the cloud. Ideal for the lab and for testing.
CIDR
The way of writing the mask with the number of bits after the slash: 192.168.1.0/24 means that the first 24 bits indicate the network. It is calculated with the Dojo IP calculator.
Client isolation
Setting that prevents devices connected to the same WiFi access point from communicating with each other: they can only see the router and the internet.
CNAME
DNS record that makes a name an alias of another: whoever queries the first receives the response of the second.
Connection tracking
The log that RouterOS uses to track every connection and assign a state to each packet: new, established, related, or invalid. It is the foundation of the stateful firewall and NAT.
CPE
Customer Premises Equipment: the device installed by the customer (antenna, modem, router) that connects them to the operator's network.
CVE
Common Vulnerabilities and Exposures: the unique code (for example CVE-2026-84411) that identifies a public software vulnerability.
CVSS
The score from 0 to 10 that measures the severity of a vulnerability: 9 and above is critical, 7 and above is high.
D
Datapath
In RouterOS WiFi and CAPsMAN configuration, the profile that determines where client traffic ends up: which bridge, which VLAN, and whether or not isolation is applied.
DDNS
A DNS name that automatically updates when the router's public address changes, so you can always reach it using the same name.
Defconf
The factory configuration of RouterOS: its rules have a comment that starts with «defconf».
Detect Internet
A RouterOS feature that classifies interfaces as LAN, WAN, or Internet and can automatically add them to interface lists.
DHCP
The protocol by which a server automatically assigns IP address, gateway, and DNS to devices. Each assignment is a lease.
DHCP snooping
Bridge or switch feature that accepts DHCP replies only from trusted ports: a rogue DHCP server connected elsewhere cannot assign addresses.
DHCPv6-PD
DHCPv6 Prefix Delegation: the mechanism by which an operator assigns a router an entire block of IPv6 networks (for example, a /56) to be divided into /64s.
DNS
The service that translates names (mikrotik.com) into IP addresses. A MikroTik router can act as a DNS server for the LAN; in that case, it must be protected by the firewall from the internet.
Dynamic rule
An entry created by RouterOS itself (for example, by a service or a script), marked with the D flag and not saved in the configuration.
E
EAP
The authentication protocol used by WPA2/WPA3-Enterprise WiFi: credentials are verified by a RADIUS server instead of a shared password.
ECMP
Equal-Cost Multi-Path: multiple routes to the same destination with the same distance, among which the router distributes traffic.
Export
The command that prints the RouterOS configuration as a text script: readable, comparable, and reusable even on a different model.
F
Fasttrack
RouterOS firewall shortcut: established connections bypass most of the processing, saving a significant amount of CPU.
Firewall
The set of rules that determines which traffic the router accepts, drops, or modifies. In RouterOS, it is located in /ip firewall (and /ipv6 firewall) and is divided into filter, nat, and mangle.
G
Gateway
The router to which a device sends traffic destined for outside its own network. The default gateway is the one used to reach the internet.
H
Horizon
Bridge port option: ports with the same horizon value do not exchange traffic with each other. This is used to isolate, for example, the access points of a guest network.
Hotspot
A public WiFi network with a captive portal: anyone connecting must authenticate on a login page before browsing. In RouterOS, it is configured with /ip hotspot.
Hotspot 2.0
Standard (certified by the Wi-Fi Alliance as Passpoint) that allows devices to automatically and securely connect to public WiFi networks without a login page.
I
ICMP
The IP service messages protocol: ping, errors, "destination unreachable". In IPv6 (ICMPv6) it is essential and must not be blocked.
Interface list
A named group of interfaces, for example WAN and LAN, to use in firewall rules and service settings instead of listing individual ports.
IP Cloud
MikroTik's free service that gives the router a DNS name of the form serial-number.sn.mynetname.net, automatically updated when the public address changes.
IPFIX
Standard formats for exporting traffic flows (who spoke with whom, how much, for how long) to a collector. In RouterOS, they are enabled with Traffic Flow.
K
KEV
Known Exploited Vulnerabilities: the CISA catalog of vulnerabilities actually exploited by attackers. A CVE in KEV must be patched immediately.
L
Lease
The assignment of an IP address by the DHCP server to a device, valid for a limited time (lease-time). Until it expires, the address remains occupied.
IPv6 address (fe80::/10) that each interface assigns to itself, valid only on the local network segment. It is essential for basic IPv6 operation.
M
MAC address
The physical address of a network card, unique for each interface. WinBox can connect to a MikroTik via MAC even when it does not have an IP address.
Mangle
The part of the RouterOS firewall that does not block traffic but marks or modifies it: connection mark, routing mark, TTL. It is the foundation of PCC and policy routing.
Masquerade
The most common form of NAT: the router replaces the private addresses of LAN devices with its own public address.
MikroTik Certifications
The official titles issued by MikroTik after a course with a certified trainer and an exam that is always taken in person. You start with the MTCNA, which is a prerequisite for all Engineer-level courses; each certificate remains valid for three years.
MTCINE
MikroTik Certified Inter-Networking Engineer: the most advanced course on inter-network routing, covering BGP and MPLS, designed for operators and large-scale networks. Requires MTCRE.
MTCIPv6E
MikroTik Certified IPv6 Engineer: the IPv6 course with RouterOS, covering addressing, routing, DHCPv6, and security. Requires MTCNA.
MTCNA
MikroTik Certified Network Associate: the foundational certification and the first step in the MikroTik certification path. It covers RouterOS, addressing, bridging, DHCP, firewall, NAT, wireless, and management tools. It is the prerequisite for all Engineer-level certifications.
MTCRE
MikroTik Certified Routing Engineer: the course on routing, from static routes to policy routing, OSPF, tunnels, and VPN. Requires MTCNA.
MTCSE
MikroTik Certified Security Engineer: the course on router and network security for MikroTik, covering hardening, attack defense, VPN, and encryption. Requires MTCNA.
MTCSWE
MikroTik Certified Switching Engineer: the course on MikroTik switches, covering bridge, VLAN, spanning tree, port isolation, and features managed by the switch chip. Requires MTCNA.
MTCTCE
MikroTik Certified Traffic Control Engineer: the course on traffic control, covering advanced firewall, mangle, QoS, and queues to manage bandwidth. Requires MTCNA.
MTCUME
MikroTik Certified User Management Engineer: the course on user management, covering hotspot, PPP, PPPoE, RADIUS, and User Manager. Requires MTCNA.
MTCWE
MikroTik Certified Wireless Engineer: the course on radio links with MikroTik: 802.11 standards, frequencies and antennas, analysis tools (scan, spectral scan, align) and link troubleshooting. Requires MTCNA.
N
NAT
Network Address Translation: the translation of IP addresses that allows many devices with private addresses to access the internet using a single public address.
Neighbor discovery
The protocol by which MikroTik (and other devices) announce themselves to network neighbors. Useful in LANs, it should be limited to internal interfaces.
Netinstall
The MikroTik program that reinstalls RouterOS from scratch over the network from a PC. It is the last resort when a router fails to boot or needs to be returned to a clean state.
Netwatch
A RouterOS tool that periodically checks whether a host responds and triggers a script when its status changes: useful for line failover.
NTP
Network Time Protocol: synchronizes the router's clock. Essential for logs, certificates, and records with reliable date and time.
O
Option 82
A DHCP option used by switches and routers to add information about the port from which the client request arrives to the request. Used by operators to identify lines.
P
Passthrough
An option for a rule (typical of mangle): the rule acts on the packet, for example by marking it or adding it to a list, and then lets it proceed to the subsequent rules.
PCC
Per Connection Classifier: a RouterOS firewall matcher that divides connections into groups using a hash. It is used to distribute traffic across multiple internet lines.
Place-before
Option of the add command in RouterOS that inserts the new entry before an existing entry instead of at the end of the list. Essential in the firewall, where the order of rules matters.
Pool
The range of addresses (or IPv6 prefixes) from which the DHCP server selects the ones to assign. In RouterOS, it is defined in /ip pool.
Port knocking
Technique that opens a port only for the address that first "knocked" by touching specific ports in a precise sequence.
Port scan
A series of attempts toward many different ports of a host, to discover which services respond.
PPPoE
A widely used access protocol for ISPs and WISPs: each customer authenticates with a username and password and receives their point-to-point connection.
PSD
Port Scan Detection: the RouterOS IPv4 firewall matcher that weighs packets directed to different ports from the same address and triggers when a threshold is exceeded.
R
RADIUS
A central authentication server: hotspot, PPPoE, and WiFi Enterprise can query it to verify whether a username and password are valid, and to log traffic.
Raw
The RouterOS firewall table that filters packets before connection tracking: it is used to discard unwanted traffic and save resources.
RouterBOOT
The boot firmware of MikroTik boards, which loads RouterOS. It is updated after RouterOS using /system routerboard upgrade.
RouterOS
The operating system for MikroTik routers and switches. Version 7 introduced, among other things, the new routing, WireGuard, and the wifi package.
Routing mark
A label that mangle applies to packets to route them according to a specific routing table. In RouterOS 7, it corresponds to a routing table.
Routing table
A separate routing table from the main one. In RouterOS 7, it is created with /routing table add and used for policy routing, for example with PCC.
S
Safe Mode
WinBox and RouterOS terminal mode: if the connection is interrupted, the router reverts all changes made in the meantime. Prevents you from being locked out.
Scheduler
The RouterOS tool that runs scripts at scheduled times or intervals, or upon router startup.
SLAAC
Stateless Address Autoconfiguration: in IPv6, devices build their own address starting from the prefix announced by the router. It only works with /64 networks.
SMTP
The email sending protocol. A MikroTik can send emails (alerts, backups) by configuring an SMTP server in /tool e-mail.
SSH
The encrypted remote terminal access protocol for the router. Along with WinBox, it is the management service to keep, but not expose to the internet.
SSID
The name of the WiFi network that appears on devices.
STARTTLS
The command that upgrades a plaintext connection to encrypted TLS, typical of email submission on port 587.
Subnet
An IP network defined by an address and a mask, for example 192.168.1.0/24. All devices in the same subnet communicate directly; to leave the subnet, they go through the gateway.
Syslog
The protocol for sending logs to an external server, where they are stored and archived. Router memory is limited and is cleared upon reboot.
System history
The log of the most recent changes to the RouterOS configuration, used by undo, redo, and Safe Mode.
T
Traceroute
Tool that displays, one by one, the routers traversed to reach a destination, leveraging the TTL of packets.
Traffic Flow
The RouterOS feature that exports traffic flows in NetFlow or IPFIX format to an external collector.
TTL
Time To Live: a counter in the IP packet that each router decrements by one. When it reaches zero, the packet is discarded: this prevents it from looping indefinitely.
U
ULA
Unique Local Address: private IPv6 addresses (fc00::/7), the equivalent of 10.x or 192.168.x networks in IPv4.
Undo and Redo
Commands that undo or redo the last change recorded in the RouterOS system history.
V
VLAN
A separate virtual network that travels over the same cables as others, distinguished by a number (tag). It is used to segment guests, offices, and devices without separate cabling.
VPN
A virtual private network: an encrypted tunnel over the internet. The correct way to manage remote routers without exposing WinBox or SSH.
W
Walled garden
In the hotspot, the list of sites that are reachable even before login, for example a payment page or a social login page.
WebFig
The web interface of RouterOS, to be used in the browser. It offers almost all the features of WinBox; if you do not use it, disable the www service.
WinBox
The official MikroTik program for configuring RouterOS with a graphical interface. It connects via IP or, if the router has no addresses, via MAC address.
WireGuard
A modern, fast, and simple VPN protocol integrated into RouterOS 7. Ideal for remote router management.
WISP
Wireless Internet Service Provider: an operator that delivers internet to customers via radio links.
WPA2 / WPA3
WiFi security systems. In Personal mode, they use a shared password; in Enterprise mode, they authenticate each user with a RADIUS server.