
Learn to connect a MikroTik router to the internet, configure DHCP on the LAN, enable NAT masquerade, and upgrade RouterOS to the latest version for secure hardening.
Protect MikroTik from physical threats by placing it in a locked control room with authorized network engineers, and disable unused interfaces and the lcd screen to prevent tampering.
Master physical security for MikroTik RouterOS v7 by configuring safe mode, renaming the router, and tracking changes with history. It covers the switch chip, bridging ports, and verifying connectivity.
Disable unused ethernet ports on the device to prevent unauthorized access. Add comments to interfaces to clarify their functions for firewall rules.
Secure MikroTik RouterOS v7 by disabling the console port and securing the LCD touchscreen. Learn to change and hide PINs and enable read-only monitoring to mitigate physical threats.
Learn to manage users on MikroTik RouterOS v7 by securing the admin account, changing the username, and setting strong passwords. Create groups with read-only privileges for engineers and assign access.
Explore MikroTik RouterOS v7 hardening by managing users, groups, and privileges; create users, assign read, write, or full access, enforce time-based access, and implement custom restrictions.
Configure time-bound and ip-based access by setting user permissions and ip firewall filters to allow logins only from approved addresses during working hours.
Discover port knocking on MikroTik routers to hide the device from unauthorized access and require a specific knock sequence to permit a connection.
Learn how to configure port knocking on MikroTik RouterOS v7 using a six-port lab, creating temporary and valid address lists, and implementing firewall rules.
Identify and disable unnecessary protocols on MikroTik RouterOS v7, scan for open ports, and harden the router by stopping risky services or changing ports to nonstandard ones to prevent attacks.
Harden MikroTik RouterOS v7 by using Nmap reconnaissance to identify open ports, disable unused protocols, change ssh and ssl ports, and restrict access to a single PC with strong keys.
Lock down MikroTik RouterOS by blocking admin login, stopping ping, and disabling neighbor discovery, and by disabling bandwidth test and ROMON to deter attacks.
Lock down MikroTik RouterOS v7 by disabling mac-based logins, restricting mac server access, and turning off mac ping, remote dns requests, neighbor discovery, romon, and bandwidth tests.
Explore MikroTik RouterOS v7 firewall, including input, output, and forward chains; implement filter, NAT, and mangle rules, and use actions like drop, accept, and jump for QoS and routing policies.
Explore MikroTik RouterOS v7 hardening by understanding connection states: new, establish, related, invalid, and entourage, and how firewall rules filter traffic, drop invalid packets, and manage established connections.
Configure firewall filter rules in MikroTik RouterOS v7 to protect the router by using a bogon address list, and by accepting established connections while dropping invalid or non-unicast traffic.
Explore the instructor’s coaching approach and access to courses, memberships, bundles, and books on my network training dot com. Stay connected through provided contact details for future courses and updates.
This course is designed for engineers who are working on MikroTik routers and who have them installed on their network.
MikroTik routers are very nice routers when it comes on the different packages that they have installed by default and features that you can configure, but they can be also very dangerous if we do not secure them correctly.
For this reason, I have designed with course with many LABs to show you how you can secure your MikroTik router and make it hard for intruders/attackers to profit from the vulnerabilities on your MikroTik router and gain access to your router and your network.
This course is based on different LABS which goes based on step-by-step and with a lot of explanation on each of the LABs.
For the whole course, I will be using the latest MikroTik RouterOS v7 for all the LABS. To be able to follow this course and repeat the LABS, you require to have only 1 MikroTik router (only in 1 LAB you need 2 MikroTik routers). You can also using virtual CHR images to follow this course, so you don't have to invest in buying a physical MikroTik router.
I look forward to see you in my course.