Users and Services
MikroTik RouterOS provides a robust system for managing users and services on your router. This includes user management for accessing and configuring the router, as well as managing various services that the router offers. Here's a detailed overview of these aspects:
1. User Management in RouterOS
Creating and Managing Users
User Accounts:
View Users:
user printLists all user accounts on the router.
Add User:
user add name=username password=password group=groupReplace username, password, and group with the desired values.
Remove User:
user remove [find name=username]Replace username with the actual username of the account to be removed.
Change User Password:
user set [find name=username] password=newpasswordReplace username and newpassword with the appropriate values.
User Groups:
View User Groups:
user group printAdd User Group:
user group add name=groupnameRemove User Group:
user group remove [find name=groupname]Assign User Group: When adding a user, specify the group:
user add name=username password=password group=groupnameUser Privileges:
Admin Group: Provides full access to all router functions.
Read Group: Allows users to view configurations but not make changes.
Write Group: Allows users to make changes but not access sensitive settings.
Access Control
User Roles: Different roles (groups) have varying levels of access. For instance, the
fullgroup has complete access, whilereadallows only viewing configurations.Login Security: Ensure strong passwords and consider limiting access by IP address for added security.
2. Services in RouterOS
RouterOS offers a range of services that can be managed via the CLI or graphical interfaces. These services include:
Network Services:
DHCP Server:
View Configuration:
ip dhcp-server printAdd DHCP Server:
ip dhcp-server add name=dhcp1 interface=ether1 address-pool=dhcp_poolConfigure Address Pool:
ip pool add name=dhcp_pool ranges=192.168.1.10-192.168.1.100DNS Server:
View DNS Configuration:
ip dns printConfigure DNS Server:
ip dns set servers=8.8.8.8,8.8.4.4NAT (Network Address Translation):
View NAT Rules:
ip firewall nat printAdd NAT Rule:
ip firewall nat add chain=srcnat action=masquerade out-interface=ether1
Management Services:
SSH:
Enable SSH Service:
ip service enable sshChange SSH Port:
ip service set ssh port=2222HTTP/HTTPS (Web Interface):
Enable Web Access:
ip service enable www ip service enable www-sslChange HTTP/HTTPS Port:
ip service set www port=8080 ip service set www-ssl port=8443Winbox:
Enable Winbox Access:
ip service enable winboxChange Winbox Port:
ip service set winbox port=8291Telnet:
Enable Telnet Service:
ip service enable telnetChange Telnet Port:
ip service set telnet port=2323
Security Considerations:
Disable Unused Services: To reduce security risks, disable services that are not in use.
Change Default Ports: Alter default ports for services to avoid common attacks.
Use Strong Passwords: Ensure that all accounts use strong, unique passwords.
3. Service Management Commands
List Services:
ip service printDisable a Service:
ip service disable service_nameReplace service_name with the actual service you wish to disable (e.g., telnet, www, etc.).
Enable a Service:
ip service enable service_nameBy effectively managing users and services, you can ensure your MikroTik router operates securely and efficiently, tailored to your specific network needs.
Keywords
MikroTik, RouterOS, RouterBOARD, wireless networking, ISP, WISP, networking equipment, routers, switches, Cloud Core Router, CCR, SXT, LTE integration, 5G, cybersecurity, network security, networking software, networking hardware, Latvia, John Trully, Arnis Riekstiņš, MikroTik Academy, MUM events, network management, hotspot, VLAN, firewall, VPN, QoS, bandwidth management, traffic shaping, wireless access point, CAPsMAN, WinBox, PoE, mesh networking, routing protocols, MPLS, OSPF, BGP, MikroTik training
میکروتیک, روتر او اس, روتر برد, شبکه بیسیم, آی اس پی, وایرلس آی اس پی, تجهیزات شبکه, روترها, سوییچها, کلود کور روتر, سی سی آر, اس ایکس تی, ادغام ال تی ای, 5G, امنیت سایبری, امنیت شبکه, نرمافزار شبکه, سختافزار شبکه, لتونی, جان ترولی, آرنیس ریکسینش, آکادمی میکروتیک, رویدادهای مام, مدیریت شبکه, هات اسپات, ویلَن, فایروال, ویپیان, کیواُاس, مدیریت پهنای باند, شکلدهی ترافیک, نقطه دسترسی بیسیم, کپزمن, وینباکس, پی او ای, شبکه مش, پروتکلهای مسیریابی, ام پی ال اس, اُ اس پی اف, بی جی پی, آموزش میکروتیک
Last updated