
Explore Mikrotik security topics and the Mikrotik certified security engineer training, and learn how to view the outline to see the course modules.
Learn how to upgrade MikroTik RouterOS to version 7.12.1 and update the router firmware by logging in, checking for updates under system package, downloading, installing, and rebooting.
Create a custom admin-level user on the MikroTik router with a strong password, remove the default admin, and restrict router login to specific IP addresses to secure access.
Disable unused router services such as SSH, FTP, and Telnet to reduce exposure, and optionally change the Winbox port from 8291 to 8292 for an extra layer of security.
Disable mac-based management access on MikroTik RouterOS to harden your production network. Remove Mac telnet, Mac winbox, and Mac ping access, then verify connectivity only via IP address.
Disable neighbor discovery to protect your Mikrotik router. Open Winbox, go to IP → neighbor discovery, set discovery setting to none, and apply; router won't appear in Winbox for attackers.
Learn to disable unused router interfaces, such as Ethernet three and four, to reduce unauthorized access, using right-click disable, and pin or turn off the LCD display.
Block ping requests by creating an IP firewall filter rule that drops ICMP traffic for the 192.168.100.0/24 network, keeping the router online with a default firewall.
Learn how to disable IPv6 neighbor discovery on MikroTik RouterOS by navigating to the IPv6 settings, unchecking the advertise MAC address option, and applying the changes.
Explore how to use the Mikrotik firewall input chain to block ICMP ping requests by creating a filter rule with chain=input, source address, protocol ICMP, and action drop.
Learn how to use the forward chain in MikroTik RouterOS firewall to block web sites, such as Facebook, by creating a layer seven protocol rule that drops matching traffic.
Explore how the Mikrotik firewall output chain handles packets originating from the router, and how to block traffic by configuring an ICMP rule on the output interface to drop packets.
Configure source net in the MikroTik IP firewall to let private-network devices access the internet. Add a rule, set the chain to source net, specify the mask, and apply.
Configure a destination net (DST net) rule to redirect tcp traffic from port 80 to 8080 on a MikroTik router, using the web proxy and firewall NAT settings to control access.
Explore how mangle mark routing enables policy based routing by tagging traffic with source address groups and steering marked packets to two different ISP gateways.
Learn to group IP addresses into a MikroTik address list, add test IPs, and drop them with a filter rule in the input chain.
View and manage active Mikrotik router connections with the IP firewall and connection tracking. Check source and destination addresses and protocols, and enable tracking to regain internet access.
Block icmp using both filter rule and Ro firewall to demonstrate how MikroTik Ro table bypasses connection tracking for improved performance and security.
Block Facebook on a Mikrotik router by creating a layer seven protocol named Facebook with its URL, then applying a drop action in a filter rule for your LAN.
Prevent icmp smurf attacks on mikrotik routers by dropping icmp traffic to a broadcast destination using an ip firewall forward rule with protocol icmp and destination address type broadcast.
Discover port knocking to hide open ports on Mikrotik routers from the internet, using a sequence of connection attempts. Learn to scan with Nmap and disable ports to block exposure.
Configure a PPTP VPN server and client on MikroTik RouterOS, including creating an IP pool, a profile, and a secret, then connect a client to verify the tunnel.
Configure l2tp vpn on mikrotik by creating an ip pool, defining a ppp profile, adding user secrets, and enabling the l2tp server with ipsec, then connect from a client.
Configure and test a sstp vpn server and client across two mikrotik routers, creating a secret, enabling the http server, and establishing an ssh tunnel for secure remote access.
learn how to create and sign server and client certificates in MikroTik RouterOS v7, mark them trusted, export them with passwords, and configure openvpn clients.
Configure an ovpn server and client on MikroTik RouterOS v7 using server and client certificates, export certificates, set up a vpn profile and secret, and connect with the vpn installer.
Learn to configure WireGuard VPN on MikroTik router by creating a WireGuard interface, assigning a VPN IP, and configuring a peer with the client, including the Windows client setup.
Configure a certificate-based IPsec IKEv2 VPN server on MikroTik RouterOS v7 from scratch. Create and sign certificates, export certificates, and set up IPsec policies and peers to enable client connections.
This final session summarizes the mtcse preparation for MikroTik security on RouterOS v6 and v7, covering firewall, cryptography, and securing router tunnels, with vendor certification insights.
This comprehensive course is designed to equip network professionals with the knowledge and skills required to pass the MikroTik Certified Security Engineer (MTCSE) exam and secure MikroTik RouterOS v7 environments. Whether you're an experienced network administrator or new to MikroTik, this course will guide you through essential security concepts and best practices.
Key Topics:
Fundamental Security Concepts: Understand core security principles, threats, vulnerabilities, and risk mitigation strategies.
Firewall Configuration: Learn to create effective firewalls, filter traffic, and implement NAT (Network Address Translation).
Secure User Access: Master user management, authentication methods, and access control lists (ACLs).
VPN (Virtual Private Network) Implementation: Set up secure VPN connections for remote access and site-to-site communication.
Intrusion Prevention Systems (IPS): Discover how to detect and prevent unauthorized access attempts.
Traffic Monitoring and Analysis: Utilize tools to analyze network traffic, identify anomalies, and troubleshoot security issues.
Security Hardening: Implement best practices to strengthen RouterOS against potential attacks.
What You'll Gain:
In-depth understanding of MikroTik RouterOS security features.
Practical experience configuring and managing secure networks.
Confidence to tackle the MTCSE exam and earn your certification.
Enhanced ability to protect networks from a wide range of threats.
Prerequisites:
Basic understanding of networking concepts (TCP/IP, routing, etc.).
Familiarity with MikroTik RouterOS is beneficial but not required.
Who Should Enroll:
Network administrators and engineers.
IT professionals responsible for network security.
Anyone seeking to obtain the MTCSE certification.
Individuals looking to enhance their knowledge of MikroTik security.
Join us and take your MikroTik security expertise to the next level!