RouterOS Fundamentals
RouterOS Is NOT GNU/Linux
RouterOS runs a Linux kernel (5.6.3) but everything above the kernel is MikroTik's proprietary nova system. This is the single most important fact for agents to internalize.
What does NOT exist on RouterOS:
- No
/bin, /usr, /etc, /var — no FHS layout
- No bash, sh, ash, zsh — no Unix shell at all
- No coreutils (
ls, cat, grep, ps, mount, ip, iptables, etc.)
- No glibc, musl, busybox
- No apt, pkg, opkg — no package manager (packages are
.npk files installed via upload + reboot)
- No
systemctl, service, init system
- No
/proc or /sys accessible from userland
- No
docker, podman — RouterOS has its own /container subsystem (7.x+)
What DOES exist:
- RouterOS CLI — its own language, not shell. Accessed via SSH, serial, WinBox, or WebFig
- REST API at
/rest/ (HTTP, port 80 by default) — the primary programmatic interface
- RouterOS scripting language (
.rsc files) — its own syntax, not bash. See Scripting reference
- WebFig (web UI) on port 80
- WinBox protocol on port 8291
Common agent mistakes to avoid:
- Do NOT try
ssh admin@host 'ls /' — it opens RouterOS CLI, not a shell
- Do NOT suggest
mount, fdisk, mkfs — use /disk commands instead
- Do NOT look for config files at
/etc/ — configuration is in the RouterOS database
- Do NOT assume
ping works the same — it's /tool/ping or /ping in CLI
- Do NOT suggest installing packages via
apt or opkg — upload .npk via SCP then /system/reboot
- See Extra packages reference for the full package list and installation pattern
RouterOS CLI Syntax
RouterOS CLI uses path-based navigation, not Unix command pipelines:
# Navigation
/ip/address/print
/interface/print
/system/resource/print
# Adding entries
/ip/address/add address=192.168.1.1/24 interface=ether1
# Modifying (by internal ID or find expression)
/ip/address/set [find interface=ether1] address=10.0.0.1/24
# Removing
/ip/address/remove [find address="192.168.1.1/24"]
# Running a command
/system/reboot
/tool/fetch url="http://example.com/file.npk" dst-path="/"
Key syntax differences from shell:
= assigns properties (no spaces around it)
[find ...] is the query expression (like WHERE)
- Strings use
"" (double quotes only)
- Comments use
#
- Variables:
:local myVar "value" and $myVar
- No pipes, no redirection, no subshell
REST API Patterns
RouterOS REST API (v7.x+) at http://HOST:PORT/rest/:
// Base pattern — use fetch() or Bun-native HTTP
const base = "http://192.168.1.1/rest";
const auth = { headers: { Authorization: `Basic ${btoa("admin:")}` } };
// GET = print (list/read)
const interfaces = await fetch(`${base}/interface`, auth).then(r => r.json());
// PUT = add (create new entry)
await fetch(`${base}/ip/address`, {
method: "PUT",
...auth,
headers: { ...auth.headers, "Content-Type": "application/json" },
body: JSON.stringify({ address: "192.168.1.1/24", interface: "ether1" }),
});
// PATCH = set (modify existing)
await fetch(`${base}/ip/address/*1`, {
method: "PATCH",
...auth,
body: JSON.stringify({ address: "10.0.0.1/24" }),
});
// DELETE = remove
await fetch(`${base}/ip/address/*1`, { method: "DELETE", ...auth });
// POST = command (execute an action)
await fetch(`${base}/ip/dns/cache/flush`, { method: "POST", ...auth });
REST gotchas:
PUT creates, PATCH updates — opposite of many APIs
- Empty password:
admin: (colon required, empty string after)
- WebFig (port 80, GET
/) returns HTTP 200 without auth — useful for health checks
- REST API (
/rest/) returns HTTP 401 without auth
- Property names may differ from CLI names (hyphens vs underscores vary by version)
.id field is *HEX format (e.g., *1, *A)
- POST to
/rest/system/reboot — no body needed for action commands
Version Scheme
Format: MAJOR.MINOR[.PATCH][betaN|rcN] — e.g., 7.22, 7.22.1, 7.23beta2, 7.22rc1
Channels (from upgrade.mikrotik.com/routeros/NEWESTa7.<channel>):
stable — production recommended
long-term — conservative, gets backported fixes
testing — pre-release candidates
development — beta features
// Resolve current version for a channel
const version = await fetch(
"https://upgrade.mikrotik.com/routeros/NEWESTa7.stable"
).then(r => r.text());
Download URLs:
- Standard:
https://download.mikrotik.com/routeros/<ver>/chr-<ver>.img.zip (x86_64)
- ARM64:
https://download.mikrotik.com/routeros/<ver>/chr-<ver>-arm64.img.zip
Architecture Names
MikroTik uses these architecture identifiers (not standard Linux arch names):
| MikroTik name |
CPU |
Common hardware |
x86 |
x86_64 |
CHR, x86-based RouterBOARDs |
arm64 |
aarch64 |
Modern ARM boards (RB5009, Chateau) |
arm |
ARMv7 |
Older ARM boards |
mipsbe |
MIPS big-endian |
Legacy RouterBOARDs |
mmips |
MIPS multi-core |
hAP ac, RB4011 |
smips |
MIPS single-core |
hAP lite, mAP |
ppc |
PowerPC |
CCR1xxx series |
tile |
Tilera |
CCR (older models) |
CHR (Cloud Hosted Router) is available only for x86 and arm64.
Default Credentials
- Username:
admin
- Password: (empty — no password)
- On first login via SSH/console, RouterOS 7.x prompts to set a password or press
a to skip
- REST API and WebFig allow empty-password access
Inspecting Hardware from RouterOS CLI
# PCI devices (the RouterOS equivalent of lspci)
/system/resource/hardware/print
# IRQ assignments (shows driver binding)
/system/resource/irq/print
# System overview
/system/resource/print
# Disk info
/disk/print
# Installed packages
/system/package/print
# IP services and ports
/ip/service/print
# Network interfaces
/interface/print
Additional Resources
Reference files:
Related skills:
- For the /container subsystem (VETH, device-mode, lifecycle): see the
routeros-container skill
- For netinstall-cli and device flashing: see the
routeros-netinstall skill
- For the /app YAML container format (7.22+): see the
routeros-app-yaml skill
- For /console/inspect tree traversal and schema generation: see the
routeros-command-tree skill
- For running CHR in QEMU (local or CI): see the
routeros-qemu-chr skill
- For QEMU user-mode emulation and macOS VM bridging: see the
tikoci-qemu-user-emulation skill
- For building OCI images for RouterOS: see the
tikoci-oci-image-building skill
MCP tools:
- For command tree browsing and property lookups: use the
rosetta MCP server tools (routeros_search, routeros_get_page, routeros_command_tree)
1---2name: routeros-fundamentals3description: RouterOS v7 domain knowledge for AI agents. Use when: working with MikroTik RouterOS, writing RouterOS CLI/script commands, calling RouterOS REST API, debugging why a Linux command fails on RouterOS, or when the user mentions MikroTik, RouterOS, CHR, or /ip /system /interface paths. Scope: RouterOS 7.x (long-term and newer) only — v6 is NOT covered and accuracy for v6 problems will be low.4---56# RouterOS Fundamentals78## RouterOS Is NOT GNU/Linux910RouterOS runs a Linux kernel (5.6.3) but **everything above the kernel is MikroTik's proprietary `nova` system**. This is the single most important fact for agents to internalize.1112**What does NOT exist on RouterOS:**13- No `/bin`, `/usr`, `/etc`, `/var` — no FHS layout14- No bash, sh, ash, zsh — no Unix shell at all15- No coreutils (`ls`, `cat`, `grep`, `ps`, `mount`, `ip`, `iptables`, etc.)16- No glibc, musl, busybox17- No apt, pkg, opkg — no package manager (packages are `.npk` files installed via upload + reboot)18- No `systemctl`, `service`, init system19- No `/proc` or `/sys` accessible from userland20- No `docker`, `podman` — RouterOS has its own `/container` subsystem (7.x+)2122**What DOES exist:**23- RouterOS CLI — its own language, not shell. Accessed via SSH, serial, WinBox, or WebFig24- REST API at `/rest/` (HTTP, port 80 by default) — the primary programmatic interface25- RouterOS scripting language (`.rsc` files) — its own syntax, not bash. See [Scripting reference](./references/scripting.md)26- WebFig (web UI) on port 8027- WinBox protocol on port 82912829**Common agent mistakes to avoid:**30- Do NOT try `ssh admin@host 'ls /'` — it opens RouterOS CLI, not a shell31- Do NOT suggest `mount`, `fdisk`, `mkfs` — use `/disk` commands instead32- Do NOT look for config files at `/etc/` — configuration is in the RouterOS database33- Do NOT assume `ping` works the same — it's `/tool/ping` or `/ping` in CLI34- Do NOT suggest installing packages via `apt` or `opkg` — upload `.npk` via SCP then `/system/reboot`35- See [Extra packages reference](./references/extra-packages.md) for the full package list and installation pattern3637## RouterOS CLI Syntax3839RouterOS CLI uses path-based navigation, not Unix command pipelines:4041```routeros42# Navigation43/ip/address/print44/interface/print45/system/resource/print4647# Adding entries48/ip/address/add address=192.168.1.1/24 interface=ether14950# Modifying (by internal ID or find expression)51/ip/address/set [find interface=ether1] address=10.0.0.1/245253# Removing54/ip/address/remove [find address="192.168.1.1/24"]5556# Running a command57/system/reboot58/tool/fetch url="http://example.com/file.npk" dst-path="/"59```6061**Key syntax differences from shell:**62- `=` assigns properties (no spaces around it)63- `[find ...]` is the query expression (like WHERE)64- Strings use `""` (double quotes only)65- Comments use `#`66- Variables: `:local myVar "value"` and `$myVar`67- No pipes, no redirection, no subshell6869## REST API Patterns7071RouterOS REST API (v7.x+) at `http://HOST:PORT/rest/`:7273```typescript74// Base pattern — use fetch() or Bun-native HTTP75const base = "http://192.168.1.1/rest";76const auth = { headers: { Authorization: `Basic ${btoa("admin:")}` } };7778// GET = print (list/read)79const interfaces = await fetch(`${base}/interface`, auth).then(r => r.json());8081// PUT = add (create new entry)82await fetch(`${base}/ip/address`, {83 method: "PUT",84 ...auth,85 headers: { ...auth.headers, "Content-Type": "application/json" },86 body: JSON.stringify({ address: "192.168.1.1/24", interface: "ether1" }),87});8889// PATCH = set (modify existing)90await fetch(`${base}/ip/address/*1`, {91 method: "PATCH",92 ...auth,93 body: JSON.stringify({ address: "10.0.0.1/24" }),94});9596// DELETE = remove97await fetch(`${base}/ip/address/*1`, { method: "DELETE", ...auth });9899// POST = command (execute an action)100await fetch(`${base}/ip/dns/cache/flush`, { method: "POST", ...auth });101```102103**REST gotchas:**104- `PUT` creates, `PATCH` updates — opposite of many APIs105- Empty password: `admin:` (colon required, empty string after)106- WebFig (port 80, GET `/`) returns HTTP 200 without auth — useful for health checks107- REST API (`/rest/`) returns HTTP 401 without auth108- Property names may differ from CLI names (hyphens vs underscores vary by version)109- `.id` field is `*HEX` format (e.g., `*1`, `*A`)110- POST to `/rest/system/reboot` — no body needed for action commands111112## Version Scheme113114Format: `MAJOR.MINOR[.PATCH][betaN|rcN]` — e.g., `7.22`, `7.22.1`, `7.23beta2`, `7.22rc1`115116**Channels** (from `upgrade.mikrotik.com/routeros/NEWESTa7.<channel>`):117- `stable` — production recommended118- `long-term` — conservative, gets backported fixes119- `testing` — pre-release candidates120- `development` — beta features121122```typescript123// Resolve current version for a channel124const version = await fetch(125 "https://upgrade.mikrotik.com/routeros/NEWESTa7.stable"126).then(r => r.text());127```128129**Download URLs:**130- Standard: `https://download.mikrotik.com/routeros/<ver>/chr-<ver>.img.zip` (x86_64)131- ARM64: `https://download.mikrotik.com/routeros/<ver>/chr-<ver>-arm64.img.zip`132133## Architecture Names134135MikroTik uses these architecture identifiers (not standard Linux arch names):136137| MikroTik name | CPU | Common hardware |138|---|---|---|139| `x86` | x86_64 | CHR, x86-based RouterBOARDs |140| `arm64` | aarch64 | Modern ARM boards (RB5009, Chateau) |141| `arm` | ARMv7 | Older ARM boards |142| `mipsbe` | MIPS big-endian | Legacy RouterBOARDs |143| `mmips` | MIPS multi-core | hAP ac, RB4011 |144| `smips` | MIPS single-core | hAP lite, mAP |145| `ppc` | PowerPC | CCR1xxx series |146| `tile` | Tilera | CCR (older models) |147148CHR (Cloud Hosted Router) is available only for `x86` and `arm64`.149150## Default Credentials151152- Username: `admin`153- Password: (empty — no password)154- On first login via SSH/console, RouterOS 7.x prompts to set a password or press `a` to skip155- REST API and WebFig allow empty-password access156157## Inspecting Hardware from RouterOS CLI158159```routeros160# PCI devices (the RouterOS equivalent of lspci)161/system/resource/hardware/print162163# IRQ assignments (shows driver binding)164/system/resource/irq/print165166# System overview167/system/resource/print168169# Disk info170/disk/print171172# Installed packages173/system/package/print174175# IP services and ports176/ip/service/print177178# Network interfaces179/interface/print180```181182## Additional Resources183184**Reference files:**185- For REST API details and `/console/inspect` command tree: see [REST API reference](./references/rest-api-patterns.md)186- For version parsing, comparison, and download URL logic: see [Version parsing reference](./references/version-parsing.md)187- For extra packages (container, iot, zerotier, etc.): see [Extra packages reference](./references/extra-packages.md)188- For device-mode (modes, feature matrix, physical confirmation): see [Device-mode reference](./references/device-mode.md)189- For RouterOS scripting language syntax: see [Scripting reference](./references/scripting.md)190191**Related skills:**192- For the /container subsystem (VETH, device-mode, lifecycle): see the `routeros-container` skill193- For netinstall-cli and device flashing: see the `routeros-netinstall` skill194- For the /app YAML container format (7.22+): see the `routeros-app-yaml` skill195- For /console/inspect tree traversal and schema generation: see the `routeros-command-tree` skill196- For running CHR in QEMU (local or CI): see the `routeros-qemu-chr` skill197- For QEMU user-mode emulation and macOS VM bridging: see the `tikoci-qemu-user-emulation` skill198- For building OCI images for RouterOS: see the `tikoci-oci-image-building` skill199200**MCP tools:**201- For command tree browsing and property lookups: use the `rosetta` MCP server tools (`routeros_search`, `routeros_get_page`, `routeros_command_tree`)