Technical & Licensing Support

Frequently Asked Questions
& Knowledge Answers

Everything you need to know about architecture, Zero-Trust security, RouterOS version support, and license registration.

MikroWizard supports multiple flexible connectivity models. For cloud-hosted or centralized installations, routers initiate an outbound encrypted WireGuard VPN tunnel back to the MikroWizard panel. This eliminates the need to expose router management ports (Winbox port 8291, SSH port 22, WebFig port 80/443) or public static IPs to the open internet.

MikroWizard runs a proprietary RADIUS Mule daemon (listening on standard RADIUS ports 1812/1813). When an engineer logs into Winbox, RouterOS delegates authentication via RADIUS. The Mule intercepts the MS-CHAPv2 credentials, validates the primary password, and verifies a 6-digit dynamic TOTP token (Google Authenticator, Authy) before issuing an Access-Accept packet.

When engineers use the in-browser Web Terminal, session traffic passes through a Linux daemon instrumented with ptrace system-call tracing. The daemon intercepts entered keystrokes and command buffers before they are transmitted to the Linux target. If a command matches an active blacklist (e.g. rm -rf / or iptables -F), execution is blocked instantly with an on-screen alert.

Community Edition is open-source and free forever, supporting unlimited devices, users, in-browser terminal, and basic backups. Pro Edition unlocks enterprise Zero-Trust PAM (kernel command blocking, session recordings, Winbox 2FA), visual diffing (ngx-diff), drag-and-drop sequence flowcharts, and white-label subscriber self-service. Premium provides 24/7 dedicated support, custom API integrations, and developer training.

Install the open-source Community edition on your Linux server. Once running, copy the unique hardware/instance serial number from the System Settings panel, and complete checkout on our official Device Registration Portal. Your license key activates automatically.

Yes. While deep PAM, WebFig proxy, and BTest features are purpose-built for MikroTik RouterOS v6 and v7, the fleet inventory and topology engine actively discovers and monitors Cisco, Linux, and other third-party switches via standard LLDP, CDP, and SNMP protocols.

Have a question not covered here?

Contact Engineering Support → Browse Full Documentation ↗