Centralized, private self-hosted remote management: Secure remote access & Zero-Trust PAM with remote Winbox 2FA, WebFig reverse proxy without public IPs, MNDP topology discovery, offline NPK firmware repository, DHCP lease tracking, WireGuard QR provisioning, and Rust btest-rs line-rate benchmarking.
MikroWizard solves what RouterOS cannot do alone: TOTP 2FA for native remote Winbox desktop access. The embedded RADIUS Mule daemon (radius.py on port 1812/1813) intercepts native remote Winbox, SSH, and WebFig MS-CHAPv2 authentication packets and validates dynamic 6-digit TOTP tokens before granting access — enabling secure remote Winbox management without VPNs or firewall modifications.


Get secure remote access to the complete MikroTik WebFig graphical configuration interface for any router — even behind double-NAT, CGNAT, or private networks — without exposing HTTP port 80/8080 or configuring public IPs. MikroWizard's HTTP/WebSocket reverse proxy (api_proxy.py) securely tunnels remote management sessions on demand.
Connect to any MikroTik router via SSH or Telnet directly inside your web browser — no PuTTY, WinBox SSH tab, SecureCRT, or local SSH key management. The xterm.js WebSocket terminal gateway (port 8201) delivers full RouterOS CLI capabilities with ANSI colors, interactive command menus, and tab completion.


MikroWizard automatically discovers your entire network topology by harvesting MikroTik MNDP (MikroTik Neighbor Discovery Protocol) tables alongside LLDP and Cisco CDP data. It dynamically constructs an interactive physics-based vis-network graph without requiring manual map maintenance.
MikroWizard maintains a local offline cache of RouterOS NPK firmware packages across all hardware architectures, enabling automated fleet-wide firmware upgrades even in completely air-gapped or isolated network segments.


MikroWizard continuously queries RouterOS DHCP server lease tables across all managed routers, recording MAC-to-IP binding histories, hostname records, lease durations, connection interfaces, and Wi-Fi signal metrics for audit and troubleshooting.
MikroWizard queries the RouterOS API and REST API in real time to collect granular device telemetry: CPU load, free RAM, HDD usage, ping latency history, active Hotspot/PPP users, interface packet counters, TX/RX rates, and config version drift — all visualized without opening WinBox.


MikroWizard's dedicated WireGuard management service (MikroWG on port 8000) configures kernel WireGuard interfaces on RouterOS v7, manages dynamic peer allocations, and auto-generates mobile client QR codes alongside RouterOS CLI peer scripts.
Standard single-threaded bandwidth test utilities struggle to saturate multi-gigabit interfaces. MikroWizard provides btest-rs, a custom Rust-compiled RouterOS Bandwidth Test engine (containerized on port 8200) supporting Curve25519 EC-SRP5 authentication compatible with RouterOS v6.43+ and v7.


MikroWizard automatically backs up RouterOS RSC (/export fine) configurations on scheduled intervals and before any automated changes. Instantly compare any two snapshots using side-by-side and unified visual diff views to spot configuration drift and restore states in one click.
Designate a reference "Golden Master" router with your ideal baseline configuration, then replicate it across any number of edge or branch routers — with granular module selection and identity exclusion filters that protect device-specific IP and identity parameters.


MikroWizard's permission profiles align directly with all 17 native RouterOS functional scopes — api, dude, ftp, local, password, policy, read, reboot, rest-api, romon, sensitive, sniff, ssh, telnet, test, tikapp, web, winbox, write — and synchronizes permissions directly with on-router user groups.
Manage your entire MikroTik fleet from a centralized inventory table: track credentials, firmware versions, RouterOS v6/v7 classification, uptime, WebFig proxy status, and API-SSL encryption. Discover unmanaged routers automatically with the subnet scanner wizard or import existing inventories in bulk via CSV.



Replace error-prone manual CLI typing with a reusable RouterOS snippet library and visual sequence flowchart builder. Standardize repetitive tasks like firewall rule updates, interface provisioning, and routing policy adjustments with automated execution audits.
[mikrowizard].Eliminate default passwords and static shared credentials across your MikroTik fleet. MikroWizard's AES-256 Fernet-encrypted vault generates cryptographically secure credentials and handles automated password rotation across router groups via API.

Deploy MikroWizard on your own infrastructure. No cloud dependency, no data leaving your premises. Full RouterOS v6 and v7 support with native Winbox 2FA, WebFig proxy, MNDP topology, offline NPK firmware, and DHCP tracking — all in one self-hosted platform.
Trademark Disclaimer: MikroTik® and RouterOS® are registered trademarks of SIA MikroTikls. MikroWizard is an independent management software solution compatible with MikroTik RouterOS and is not affiliated with or endorsed by SIA MikroTikls.