In short: Safe Mode is the safety net of RouterOS: while it is active, the router logs every change and, if the session that made them drops, it automatically rolls them back. You enable it with Ctrl+X (or F4) in the terminal and with the Safe Mode button in WinBox. It holds a maximum of 100 actions and does not cover commands that restart the router.

What is Safe Mode?

It is a parachute tied to your session. You are working on a remote router, you write a wrong firewall rule, the connection drops: without Safe Mode you are locked out, and the only way in is to go on-site or call someone with console access. With Safe Mode, the router detects that the session died unexpectedly and restores the configuration to how it was before you started.

The manual is clear: once the connection is already cut, there is no way to undo the last change. Safe Mode exists to reduce exactly that risk. It does not eliminate it: it reduces it, and later we will see where its coverage ends.

How do you enable it from the terminal?

Press Ctrl+X (or F4) at the prompt. The router responds Taking Safe Mode session... Success! and the prompt displays <SAFE>.

[admin@MikroTik] >           (premi Ctrl+X)
Taking Safe Mode session... Success!
[admin@MikroTik] <SAFE>

From this point on, every change is “on trial”. To exit, you have three options, and they do different things:

  • Ctrl+X again: the router responds Releasing Safe Mode... Success! and the changes are kept. This is the gesture that says “okay, I confirm”;
  • Ctrl+D: closes the session and undoes all changes made in Safe Mode;
  • /quit: the router warns you You are in Safe Mode. Quitting will unroll changes. Quit? [y/N]. Answer y and the changes are undone; answer n and you stay connected, still in Safe Mode. The manual still says that /quit does not undo: on RouterOS 7.24.5 this is no longer the case.

Remember it this way: the only way to keep the changes is Ctrl+X. Any other exit (Ctrl+D, /quit, closing the terminal, the connection dropping) means “go back” for the router.

And in WinBox?

In WinBox there is the Safe Mode button in the top bar, next to Undo and Redo. You press it, it stays on, and from that moment the same mechanism as in the terminal applies. Press it again to exit and confirm. In WebFig you find the same button in the top bar.

Safe Mode is not tied to a window: it is tied to the router. The manual states that all changes made while the router is in Safe Mode are undone, including those made from other sessions. If a colleague changes something via SSH while you are holding Safe Mode in WinBox and your session drops, their work is rolled back too.

What happens if the connection drops?

The router undoes everything. If the session closes cleanly, for example because you close the terminal, in the lab the changes are gone immediately. If instead the network drops and the router no longer sees any traffic, the manual indicates that the rollback happens “after a while”: the TCP timeout is 9 minutes.

In practice: you have locked yourself out, the router no longer responds, and for a few minutes nothing happens. Do not panic and do not power-cycle the router if someone is on-site. Wait. Within about ten minutes the configuration returns to how it was and you can get back in.

⚠️ Warning: the rollback only triggers if the session terminates abnormally. If you exit with Ctrl+X, for the router you have confirmed.

How do I see what would be undone?

You can see it in /system history: actions performed in Safe Mode have the F (floating-undo) flag, meaning they are “automatically undoable”.

[admin@MikroTik] <SAFE> /ip firewall address-list add list=prova address=203.0.113.5
[admin@MikroTik] <SAFE> /system history print where action~"address"
Flags: U - UNDOABLE, F - FLOATING-UNDO
Columns: ACTION, BY, POLICY, TIME
  ACTION                      BY     POLICY  TIME
F address list entry added    admin  write   2026-10-10 17:09:06
U address list entry removed  admin  write   2026-10-10 17:01:29

Actions with the U flag, on the other hand, are already confirmed: they do not disappear on their own, but you can still remove them manually with /undo.

This is the same log used by the Undo and Redo buttons in WinBox. /system history print detail shows, for each action, the exact command that would be executed to undo or redo it, even if you performed the action from WinBox. You can find how undo and redo work in the MikroTik manual: Configuration Management.

How many changes does it keep in memory?

A maximum of 100 actions: this is the size of the history. If you perform more, the router automatically removes you from Safe Mode and does not undo anything. Warning: every command inside a loop counts. In the lab, a :for that adds 50 entries to an address list was entirely undone when the session closed; with 105 entries, all remained, and the prompt still showed <SAFE>. From that moment on, you are without network, and you might not even notice.

The manual recommends working in small steps. The trick is to press Ctrl+X twice: you exit (confirming what you have done so far) and immediately re-enter, with the action list empty. You have another 100 actions of margin, and the already tested part will not be rolled back if the next step goes wrong.

What happens if another user is already in Safe Mode?

Safe Mode is held by only one session at a time. According to the manual, if you request it while someone else has it, RouterOS lets you choose:

Hijacking Safe Mode from someone - unroll/release/don't take it [u/r/d]:
  • u (unroll): undo all Safe Mode changes of the other user and take over Safe Mode;
  • r (release): keep their changes (they become confirmed) and take over Safe Mode. The other user sees the message [Safe mode released by another user];
  • d: leave everything as it is and do not take over.

In the lab, with the same user in two sessions, the second one took over Safe Mode with a simple Success!, without any prompt, and the changes from the first session were undone. So do not count on the prompt: if you are working in pairs on the same router, talk to each other first.

What does it NOT cover?

Safe Mode lives within the session and preserves configuration changes. For this reason, the manual states that it is ignored for commands that require a reboot, such as resetting the configuration or restoring a backup. A /system reset-configuration launched in Safe Mode is not undone when the session drops: the router simply reboots. (If you need a reset for educational purposes, use the one from Basic Hardening.)

It does not protect you either once you have already confirmed: after Ctrl+X or exceeding the 100-action limit, the changes are definitive. Only /undo remains, and if you can no longer log in, another access method.

When do I use it?

Every time the change might cut the branch you are sitting on:

  • remote firewall: the drop rule at the bottom of the input chain, the order of the rules, an access address list. This is the case of the minimal hardening firewall and port knocking: if the lock doesn’t open, the router locks you out;
  • changing the address on the interface you are connected to, for example /ip address add address=10.6.0.2/12 interface=ether1 (the addresses are those of the lab: calculate yours with the IP calculator) and then removing the old one;
  • VLAN on the management port: moving the port you are coming from under a bridge with VLAN filtering is the classic way to disappear;
  • scripts pasted into the terminal: ten lines copied from a note make ten changes, and one wrong one is enough;
  • working on the link you are passing through: even a wireless scan on a remote router must be done with Safe Mode enabled, if you touch anything else in the same session.

The right gesture is always the same: Safe Mode, modify, open a new second session and verify that you can get in. Only then do you confirm with Ctrl+X.

What are the typical errors?

  • Confirming too early. You apply the rule, the open session continues to work (already established connections pass), you press Ctrl+X. Then you close and you can’t get back in. Always test with a new connection before confirming;
  • Exiting with /quit thinking you are confirming. In Safe Mode /quit cancels, and it even asks you. To keep the changes you need Ctrl+X;
  • Pasting a long script. Beyond 100 actions the Safe Mode turns off by itself and without going back. Split the script and use Ctrl+X twice between one block and the other;
  • Rebooting after being locked out. You have locked yourself out and ask someone to cut the power: wait for the timeout minutes before deciding that the Safe Mode did not work;
  • Trusting it for the reset. Configuration reset and backup restoration pass through reboot: the Safe Mode does not cover them.

Tested in the lab on a routerboard with RouterOS 7.24.5 (stable), from SSH terminal: Safe Mode with Ctrl+X, confirmation with the second Ctrl+X, cancellation with Ctrl+D, with /quit (answer y; with n you stay in Safe Mode) and with the session closed abruptly, flag F in /system history, limit of 100 actions with a :for (50 cancelled, 105 remaining), second session of the same user that takes the Safe Mode. The 9-minute timeout, WebFig and the u/r/d choice are from the documentation.

Frequently asked questions

How do I activate Safe Mode from the terminal?

With Ctrl+X or F4. The router responds Taking Safe Mode session... Success! and the prompt shows <SAFE>. Another Ctrl+X exits and confirms the changes.

How long does it take the router to cancel the changes after a disconnection?

If the session closes cleanly, immediately. If the network drops and the router does not know that you have disappeared, the manual indicates the TCP timeout of 9 minutes; after that, the changes made in Safe Mode are cancelled.

How do I exit Safe Mode keeping the changes?

Only with Ctrl+X. Ctrl+D and /quit close the session and cancel everything you have done in Safe Mode; /quit asks you first.

How many changes can Safe Mode undo?

Up to 100 actions, which is the capacity of the history. Beyond that, the router exits Safe Mode on its own and does not undo anything. Pressing Ctrl+X twice clears the list and starts over from scratch.

Does Safe Mode undo a configuration reset?

No. Safe Mode is ignored for commands that require a reboot, such as resetting the configuration or restoring a backup.