How to secure a MikroTik router: a hardening checklist
Last updated: 2 October 2026
Most hacked MikroTik routers were not broken into by clever tricks. They had an old RouterOS version, the admin user with a weak password, and Winbox or DNS open to the internet. This checklist closes those doors in about ten minutes.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
In the examples ether1 is the internet side and 192.168.88.0/24 is your LAN.
1. A new admin user with a strong password
Attackers try the name admin first. Make a user with another name, log in with it, then disable the old one:
/user add name=owner group=full password="A-long-password-here"
/user disable admin
/user printLog in as the new user before you disable admin, to be sure it works. Give helpers their own user with group=read or group=write instead of sharing yours.
2. Turn off services you do not use
/ip service print
/ip service disable telnet,ftp,www,api,api-sslKeep www if you use WebFig, and api if a tool you run needs it. Everything left enabled should be limited in the next step.
3. Limit Winbox and SSH by address
/ip service set winbox address=192.168.88.0/24
/ip service set ssh address=192.168.88.0/24Now those services answer only to your LAN. Several ranges can be given, separated by commas.
4. MAC access and discovery on the LAN only
MAC Winbox and neighbor discovery are handy on your own network and a gift to anyone on the WAN side:
/interface list add name=LAN
/interface list member add list=LAN interface=bridge
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN
/tool mac-server ping set enabled=no
/ip neighbor discovery-settings set discover-interface-list=LANIf a list named LAN already exists (it does in the default configuration), skip the first two lines.
5. Close the router to the internet
The input chain should end by dropping everything that arrives on the WAN and was not asked for. That one rule closes Winbox, SSH and DNS from outside at once:
/ip firewall filter
add chain=input connection-state=established,related action=accept
add chain=input connection-state=invalid action=drop
add chain=input protocol=icmp action=accept
add chain=input in-interface=ether1 action=drop comment="nothing else from the internet"The full set with the forward chain is in basic firewall. If the router answers DNS for your clients, read the open-resolver part of DNS setup.
6. Small things that are often left on
/tool bandwidth-server set enabled=no
/ip proxy set enabled=no
/ip socks set enabled=no
/ip upnp set enabled=no
/ip ssh set strong-crypto=yesThe bandwidth test server is on by default and lets anyone who can reach it load your processor. Proxy and SOCKS are off by default; if you find them on and did not do it, the router has probably been tampered with.
7. Upgrade RouterOS
/system package update check-for-updatesOld versions have known holes that are attacked automatically. See how to upgrade RouterOS.
8. Back up, and keep the copy elsewhere
/system backup save name=after-hardeningDrag the file to your computer. See backup and restore.
Signs that someone was already in
/user print
/system scheduler print
/system script print
/ip firewall nat print
/file print
/log print where topics~"system"Look for users, schedulers, scripts or NAT rules you did not create, and for login failures from unknown addresses in the log. If you find any, the safe cure is a clean reinstall with Netinstall and new passwords.
Where RadiusNest fits
One common reason routers end up with weak, widely shared passwords is that staff need them to add users. With RadiusNest your staff and resellers get their own logins to a dashboard to create customers, print vouchers and take renewals, so nobody except you needs the router password. The router is connected with one pasted command and needs no public IP address, so Winbox never has to be opened to the internet for it.
Start the free trial See pricing
Questions and answers
Should I change the Winbox port?
It cuts down noise in the log but it is not protection. Limiting Winbox to your own addresses and dropping WAN input is what protects the router.
Can I delete the admin user?
Yes, once another user with full rights exists and you have logged in with it. Disabling it has the same effect and is easier to undo.
How do I know if my MikroTik was hacked?
Look for unknown users, schedulers, scripts, NAT rules, files, or a proxy or SOCKS service you did not enable. If in doubt, reinstall with Netinstall and set new passwords.