RouterOS Fundamentals
RouterOS Is NOT GNU/Linux
RouterOS runs a Linux kernel (5.6.3) but everything above the kernel is MikroTik's proprietary nova system. This is the single most important fact for agents to internalize.
What does NOT exist on RouterOS:
- No
/bin, /usr, /etc, /var — no FHS layout
- No bash, sh, ash, zsh — no Unix shell at all
- No coreutils (
ls, cat, grep, ps, mount, ip, iptables, etc.)
- No glibc, musl, busybox
- No apt, pkg, opkg — no package manager (packages are
.npk files installed via upload + reboot)
- No
systemctl, service, init system
- No
/proc or /sys accessible from userland
- No
docker, podman — RouterOS has its own /container subsystem (7.x+)
What DOES exist:
- RouterOS CLI — its own language, not shell. Accessed via SSH, serial, WinBox, or WebFig
- REST API at
/rest/ (HTTP, port 80 by default) — the primary programmatic interface
- RouterOS scripting language (
.rsc files) — its own syntax, not bash. See the routeros-scripting skill and Scripting reference
- WebFig (web UI) on port 80
- WinBox protocol on port 8291
Common agent mistakes to avoid:
- Do NOT try
ssh admin@host 'ls /' — it opens RouterOS CLI, not a shell
- Do NOT suggest
mount, fdisk, mkfs — use /disk commands instead
- Do NOT look for config files at
/etc/ — configuration is in the RouterOS database
- Do NOT assume
ping works the same — it's /tool/ping or /ping in CLI
- Do NOT suggest installing packages via
apt or opkg — upload .npk via SCP then /system/package/apply-changes (7.18+) or /system/reboot (<7.18)
- See Extra packages reference for the full package list and installation pattern
RouterOS CLI Syntax
RouterOS CLI uses path-based navigation, not Unix command pipelines:
# Navigation
/ip/address/print
/interface/print
/system/resource/print
# Adding entries
/ip/address/add address=192.168.1.1/24 interface=ether1
# Modifying (by internal ID or find expression)
/ip/address/set [find interface=ether1] address=10.0.0.1/24
# Removing
/ip/address/remove [find address="192.168.1.1/24"]
# Running a command
/system/reboot
/tool/fetch url="http://example.com/file.npk" dst-path="/"
Key syntax differences from shell:
= assigns properties (no spaces around it)
[find ...] is the query expression (like WHERE)
- Interactive
print row numbers are not script-safe object IDs; use [find ...] or *HEX internal IDs
- Strings use
"" (double quotes only)
- Comments use
#
- Variables:
:local myVar "value" and $myVar
- No pipes, no redirection, no subshell
REST API
RouterOS REST API at http://HOST:PORT/rest/. HTTP verbs map non-standardly:
| HTTP |
RouterOS Action |
CLI Equiv |
GET |
print (list/read) |
/path/print |
PUT |
add (create) |
/path/add |
PATCH |
set (update) |
/path/set |
DELETE |
remove |
/path/remove |
POST |
command (execute) |
/path/command |
Key gotchas:
PUT creates (NOT updates) — opposite of many REST APIs
- Empty password auth:
admin: (colon required, nothing after)
- WebFig root (
GET /) returns HTTP 200 without auth — use as health check
- REST API (
/rest/) requires auth (HTTP 401 without it)
.id field is *HEX format (e.g., *1, *A)
See REST API reference for full patterns, error handling, filtering, POST commands, and /console/inspect.
Version Scheme
Format: MAJOR.MINOR[.PATCH][betaN|rcN] — e.g., 7.22, 7.22.1, 7.23beta2, 7.22rc1
Channels: stable / long-term / testing / development
Version endpoint (plain text): https://upgrade.mikrotik.com/routeros/NEWESTa7.<channel>
For version parsing, comparison, download URLs, and package naming: see Version parsing reference.
Architecture Names
MikroTik uses these architecture identifiers (not standard Linux arch names):
| MikroTik name |
CPU |
Common hardware |
x86 |
x86_64 |
CHR, x86-based RouterBOARDs |
arm64 |
aarch64 |
Modern ARM boards (RB5009, Chateau) |
arm |
ARMv7 |
Older ARM boards |
mipsbe |
MIPS big-endian |
Legacy RouterBOARDs |
mmips |
MIPS multi-core |
hAP ac, RB4011 |
smips |
MIPS single-core |
hAP lite, mAP |
ppc |
PowerPC |
CCR1xxx series |
tile |
Tilera |
CCR (older models) |
CHR (Cloud Hosted Router) is available only for x86 and arm64.
Default Credentials
- Username:
admin
- Password: (empty — no password)
- On first login via SSH/console, RouterOS 7.x prompts to set a password or press
a to skip
- REST API and WebFig allow empty-password access
Inspecting Hardware from RouterOS CLI
# PCI devices (the RouterOS equivalent of lspci)
/system/resource/hardware/print
# IRQ assignments (shows driver binding)
/system/resource/irq/print
# System overview
/system/resource/print
# Disk info
/disk/print
# Installed packages
/system/package/print
# IP services and ports
/ip/service/print
# Network interfaces
/interface/print
Additional Resources
Reference files:
- New official manual home: https://manual.mikrotik.com/. The new site is replacing older Confluence-based
help.mikrotik.com docs and includes a CLI Reference section at https://manual.mikrotik.com/docs/CLI%20Reference/.
- For REST API details and
/console/inspect command tree: see REST API reference
- For version parsing, comparison, and download URL logic: see Version parsing reference
- For extra packages (container, iot, zerotier, etc.): see Extra packages reference
- For device-mode (modes, feature matrix, physical confirmation): see Device-mode reference
- For RouterOS scripting language syntax: see Scripting reference
- For user management, SSH keys, admin account: see Users REST reference
- For IP addressing, routing, DHCP, DNS, interfaces: see Networking REST reference
- For firewall filter/NAT/mangle and rule ordering: see Firewall REST reference
- For Bun runtime bugs affecting HTTP (req.destroy, pool, secrets): see Bun runtime gotchas
Related skills:
- For RouterOS scripting and
.rsc/CLI config automation gotchas: see the routeros-scripting skill
- For the /container subsystem (VETH, device-mode, lifecycle): see the
routeros-container skill
- For netinstall-cli and device flashing: see the
routeros-netinstall skill
- For the /app YAML container format (7.22+): see the
routeros-app-yaml skill
- For /console/inspect tree traversal and schema generation: see the
routeros-command-tree skill
- For running CHR in QEMU (local or CI): see the
routeros-qemu-chr skill
- For packet capture, /tool/sniffer, and TZSP streaming: see the
routeros-sniffer skill
MCP tools:
- For command tree browsing and property lookups: use the
rosetta MCP server tools (routeros_search, routeros_get_page, routeros_command_tree)
1---2name: routeros-fundamentals3description: RouterOS v7 domain knowledge for AI agents. Use when: working with MikroTik RouterOS, writing RouterOS CLI/script commands, calling RouterOS REST API, debugging why a Linux command fails on RouterOS, or when the user mentions MikroTik, RouterOS, CHR, or /ip /system /interface paths. Scope: RouterOS 7.x (long-term and newer) only — v6 is NOT covered and accuracy for v6 problems will be low.4---5
6# RouterOS Fundamentals
7
8## RouterOS Is NOT GNU/Linux
9
10RouterOS runs a Linux kernel (5.6.3) but **everything above the kernel is MikroTik's proprietary `nova` system**. This is the single most important fact for agents to internalize.
11
12**What does NOT exist on RouterOS:**
13
14- No `/bin`, `/usr`, `/etc`, `/var` — no FHS layout
15- No bash, sh, ash, zsh — no Unix shell at all
16- No coreutils (`ls`, `cat`, `grep`, `ps`, `mount`, `ip`, `iptables`, etc.)
17- No glibc, musl, busybox
18- No apt, pkg, opkg — no package manager (packages are `.npk` files installed via upload + reboot)
19- No `systemctl`, `service`, init system
20- No `/proc` or `/sys` accessible from userland
21- No `docker`, `podman` — RouterOS has its own `/container` subsystem (7.x+)
22
23**What DOES exist:**
24
25- RouterOS CLI — its own language, not shell. Accessed via SSH, serial, WinBox, or WebFig
26- REST API at `/rest/` (HTTP, port 80 by default) — the primary programmatic interface
27- RouterOS scripting language (`.rsc` files) — its own syntax, not bash. See the `routeros-scripting` skill and [Scripting reference](./references/scripting.md)
28- WebFig (web UI) on port 80
29- WinBox protocol on port 8291
30
31**Common agent mistakes to avoid:**
32
33- Do NOT try `ssh admin@host 'ls /'` — it opens RouterOS CLI, not a shell
34- Do NOT suggest `mount`, `fdisk`, `mkfs` — use `/disk` commands instead
35- Do NOT look for config files at `/etc/` — configuration is in the RouterOS database
36- Do NOT assume `ping` works the same — it's `/tool/ping` or `/ping` in CLI
37- Do NOT suggest installing packages via `apt` or `opkg` — upload `.npk` via SCP then `/system/package/apply-changes` (7.18+) or `/system/reboot` (<7.18)
38- See [Extra packages reference](./references/extra-packages.md) for the full package list and installation pattern
39
40## RouterOS CLI Syntax
41
42RouterOS CLI uses path-based navigation, not Unix command pipelines:
43
44```routeros
45# Navigation
46/ip/address/print
47/interface/print
48/system/resource/print
49
50# Adding entries
51/ip/address/add address=192.168.1.1/24 interface=ether1
52
53# Modifying (by internal ID or find expression)
54/ip/address/set [find interface=ether1] address=10.0.0.1/24
55
56# Removing
57/ip/address/remove [find address="192.168.1.1/24"]
58
59# Running a command
60/system/reboot
61/tool/fetch url="http://example.com/file.npk" dst-path="/"
62```
63
64**Key syntax differences from shell:**
65
66- `=` assigns properties (no spaces around it)
67- `[find ...]` is the query expression (like WHERE)
68- Interactive `print` row numbers are not script-safe object IDs; use `[find ...]` or `*HEX` internal IDs
69- Strings use `""` (double quotes only)
70- Comments use `#`
71- Variables: `:local myVar "value"` and `$myVar`
72- No pipes, no redirection, no subshell
73
74## REST API
75
76RouterOS REST API at `http://HOST:PORT/rest/`. HTTP verbs map non-standardly:
77
78| HTTP | RouterOS Action | CLI Equiv |
79|---|---|---|
80| `GET` | print (list/read) | `/path/print` |
81| `PUT` | **add (create)** | `/path/add` |
82| `PATCH` | set (update) | `/path/set` |
83| `DELETE` | remove | `/path/remove` |
84| `POST` | command (execute) | `/path/command` |
85
86**Key gotchas:**
87
88- `PUT` creates (NOT updates) — opposite of many REST APIs
89- Empty password auth: `admin:` (colon required, nothing after)
90- WebFig root (`GET /`) returns HTTP 200 without auth — use as health check
91- REST API (`/rest/`) requires auth (HTTP 401 without it)
92- `.id` field is `*HEX` format (e.g., `*1`, `*A`)
93
94See [REST API reference](./references/rest-api-patterns.md) for full patterns, error handling, filtering, POST commands, and `/console/inspect`.
95
96## Version Scheme
97
98Format: `MAJOR.MINOR[.PATCH][betaN|rcN]` — e.g., `7.22`, `7.22.1`, `7.23beta2`, `7.22rc1`
99
100**Channels:** `stable` / `long-term` / `testing` / `development`
101
102Version endpoint (plain text): `https://upgrade.mikrotik.com/routeros/NEWESTa7.<channel>`
103
104For version parsing, comparison, download URLs, and package naming: see [Version parsing reference](./references/version-parsing.md).
105
106## Architecture Names
107
108MikroTik uses these architecture identifiers (not standard Linux arch names):
109
110| MikroTik name | CPU | Common hardware |
111|---|---|---|
112| `x86` | x86_64 | CHR, x86-based RouterBOARDs |
113| `arm64` | aarch64 | Modern ARM boards (RB5009, Chateau) |
114| `arm` | ARMv7 | Older ARM boards |
115| `mipsbe` | MIPS big-endian | Legacy RouterBOARDs |
116| `mmips` | MIPS multi-core | hAP ac, RB4011 |
117| `smips` | MIPS single-core | hAP lite, mAP |
118| `ppc` | PowerPC | CCR1xxx series |
119| `tile` | Tilera | CCR (older models) |
120
121CHR (Cloud Hosted Router) is available only for `x86` and `arm64`.
122
123## Default Credentials
124
125- Username: `admin`
126- Password: (empty — no password)
127- On first login via SSH/console, RouterOS 7.x prompts to set a password or press `a` to skip
128- REST API and WebFig allow empty-password access
129
130## Inspecting Hardware from RouterOS CLI
131
132```routeros
133# PCI devices (the RouterOS equivalent of lspci)
134/system/resource/hardware/print
135
136# IRQ assignments (shows driver binding)
137/system/resource/irq/print
138
139# System overview
140/system/resource/print
141
142# Disk info
143/disk/print
144
145# Installed packages
146/system/package/print
147
148# IP services and ports
149/ip/service/print
150
151# Network interfaces
152/interface/print
153```
154
155## Additional Resources
156
157**Reference files:**
158
159- New official manual home: <https://manual.mikrotik.com/>. The new site is replacing older Confluence-based `help.mikrotik.com` docs and includes a CLI Reference section at <https://manual.mikrotik.com/docs/CLI%20Reference/>.
160- For REST API details and `/console/inspect` command tree: see [REST API reference](./references/rest-api-patterns.md)
161- For version parsing, comparison, and download URL logic: see [Version parsing reference](./references/version-parsing.md)
162- For extra packages (container, iot, zerotier, etc.): see [Extra packages reference](./references/extra-packages.md)
163- For device-mode (modes, feature matrix, physical confirmation): see [Device-mode reference](./references/device-mode.md)
164- For RouterOS scripting language syntax: see [Scripting reference](./references/scripting.md)
165- For user management, SSH keys, admin account: see [Users REST reference](./references/routeros-users-rest.md)
166- For IP addressing, routing, DHCP, DNS, interfaces: see [Networking REST reference](./references/routeros-networking-rest.md)
167- For firewall filter/NAT/mangle and rule ordering: see [Firewall REST reference](./references/routeros-firewall-rest.md)
168- For Bun runtime bugs affecting HTTP (req.destroy, pool, secrets): see [Bun runtime gotchas](./references/bun-runtime-gotchas.md)
169
170**Related skills:**
171
172- For RouterOS scripting and `.rsc`/CLI config automation gotchas: see the `routeros-scripting` skill
173- For the /container subsystem (VETH, device-mode, lifecycle): see the `routeros-container` skill
174- For netinstall-cli and device flashing: see the `routeros-netinstall` skill
175- For the /app YAML container format (7.22+): see the `routeros-app-yaml` skill
176- For /console/inspect tree traversal and schema generation: see the `routeros-command-tree` skill
177- For running CHR in QEMU (local or CI): see the `routeros-qemu-chr` skill
178- For packet capture, /tool/sniffer, and TZSP streaming: see the `routeros-sniffer` skill
179
180**MCP tools:**
181
182- For command tree browsing and property lookups: use the `rosetta` MCP server tools (`routeros_search`, `routeros_get_page`, `routeros_command_tree`)