RadiusNest › Guides

MikroTik CHR: install RouterOS on a VPS or virtual machine

Last updated: 11 October 2026

CHR (Cloud Hosted Router) is RouterOS for virtual machines and cloud servers. On a server at your site (under Proxmox, VMware or Hyper-V) it is often the main PPPoE or hotspot router; on your laptop it is a lab to test commands before you touch a live router.

In VirtualBox or VMware (a lab)

  1. From mikrotik.com/download, under Cloud Hosted Router, take the disk image for your program (VDI for VirtualBox, VMDK for VMware).
  2. Create a virtual machine of type "Other Linux, 64-bit" with 256 MB of memory or more, and use the downloaded file as its disk.
  3. Give it a network adapter, start it, and log in as admin. Set a password when asked.

On a VPS

Most VPS providers do not list RouterOS. The usual way is to write the CHR image over the VPS disk from the provider's rescue system. This erases everything on the server. Use a new, empty VPS whose provider offers a rescue or recovery console.

# in the rescue system of the VPS
lsblk                          # find the disk: usually vda or sda
V=7.20                         # the current stable version shown on mikrotik.com/download
wget https://download.mikrotik.com/routeros/$V/chr-$V.img.zip
unzip chr-$V.img.zip
dd if=chr-$V.img of=/dev/vda bs=4M oflag=sync
reboot

Change vda if lsblk showed another disk name, and the version to the one on the download page. After the reboot, open the provider's console (VNC), log in as admin, set a password at once, and check that the server got its address:

/ip address print
/ip route print

If there is no address, add the one your provider gave you by hand, with the gateway as the default route.

Secure it before anything else

A CHR on the internet is scanned within minutes. Keep only what you use and limit it to your addresses:

/ip service disable telnet,ftp,www,api,api-ssl
/ip service set winbox address=198.51.100.25/32
/ip service set ssh address=198.51.100.25/32
/ip dns set allow-remote-requests=no

Then follow the hardening checklist and safe remote access.

The 1 Mbps trap: licences

LicenceSpeed limit (upload per interface)
Free1 Mbit/s
P11 Gbit/s
P1010 Gbit/s
P-Unlimitednone

A new CHR is limited to 1 Mbit/s per interface until you license it. That is enough for a lab and far too little for real traffic. For 60 days you can try a paid level free: create an account on mikrotik.com and run:

/system license renew
/system license print

Buy the licence before the trial ends; if you buy during the trial, run /system license renew again so the CHR knows. Prices and rules: MikroTik licence levels.

Where RadiusNest fits

A CHR runs the same RouterOS as a hardware router, so it connects to RadiusNest the same way: add it as a router, choose v7, and paste the one command. A CHR on a server at your site then works as a PPPoE or hotspot router whose users and packages are managed in RadiusNest.

Start the free trial See pricing

Questions and answers

Is MikroTik CHR free?

It can run free forever, but the free licence limits each interface to 1 Mbit/s upload. A 60-day trial of the paid levels is free.

How much memory does CHR need?

It starts with 256 MB. Give it more if it will carry many PPPoE customers or a large routing table.

Can I put CHR on any VPS?

Only where you can write your own disk image, usually from a rescue system. Some providers do not allow it; check before you buy.

Related guides

Start the free trial See pricing