Pillar 1 • Remote Access & Privileged Access Management

Zero-Trust Remote Access &
Privileged Access Management (PAM)

Secure remote access without open management ports, shared credentials, or unrecorded sessions. Enforce remote Winbox 2FA via RADIUS Mule, in-browser HTML5 terminal access, kernel-level command blocking, and Asciinema keystroke forensics.

Access

Zero-Client In-Browser HTML5 Terminal Gateway

Engineers open terminal sessions directly in their browser powered by xterm.js over WebSockets. Router passwords are encrypted with AES-256 and injected into sessions automatically without user exposure.

  • Zero local SSH client software or VPN client installations required.
  • No exposed router management ports (port 22 or 23) needed on the public internet.
  • Multi-tab terminal switching across distributed core routers.
In-Browser Zero-Client Terminal Gateway
Inspect High-Res Screen

Interactive Terminal Session: Live WebSockets CLI connected to MikroTik CHR-Tower01 rendering active RouterOS prompt.

Reverse WebFig Proxy Interface
Inspect High-Res Screen

Multiplexed WebFig GUI: Embedded RouterOS WebFig GUI proxied through secure backend tunnels without public IPs.

GUI Proxy

Secure WebFig Reverse Proxy (Zero Port Exposure)

Access the full graphical MikroTik WebFig interface for any router in your fleet without configuring firewall NAT port forwardings or assigning static public IPs to edge devices.

  • Multiplexes HTTP/WebSocket WebFig traffic through the central MikroWizard engine.
  • Protects routers behind CGNAT and dynamic cellular uplinks.
Policy Enforcement

Kernel-Level System Call Command Interception

Prevent catastrophic operational accidents before they happen. Terminal sessions pass through a Linux daemon instrumented with ptrace system-call tracing that evaluates keystroke buffers against active regex policies.

  • Instantly blocks destructive commands like rm -rf / or unauthorized reboots.
  • Granular regex matchers with custom warning alerts and audit alerts.
Security Policies List
Inspect High-Res Screen

Security Policy Engine: Rule definitions specifying allowed and blocked command patterns across fleet groups.

Live Session Sharing Modal
Inspect High-Res Screen

Multi-Operator Sharing: Generate guest invitation tokens with granular Owner, Collaborator, and Read-Only Observer roles.

Collaboration

Real-Time Terminal Collaboration Rooms

Troubleshoot complex network incidents together. Multiple engineers can connect to the same live CLI terminal simultaneously with defined role-based interaction permissions.

  • Owner Role: Initiates session, controls invite permissions, and retains killswitch authority.
  • Collaborator Role: Interactive write access for pair troubleshooting.
  • Observer Role: View-only access for training, auditing, and junior shadow sessions.
Audit Forensics

Asciinema Keystroke Recording & Web Player

Every character typed and every output byte rendered during terminal sessions is captured in lightweight, tamper-evident Asciinema v2 format (.cast).

  • In-browser interactive player with timeline scrubber, play/pause, and 0.5x to 4x speed multipliers.
  • High compression ratio: hours of session history stored in mere kilobytes instead of gigabytes of heavy video.
Asciinema Session Playback Player
Inspect High-Res Screen

Session Forensics Player: Scrubbable playback modal rendering precise terminal state reconstruction.

Active PAM Sessions Console
Inspect High-Res Screen

Active Session Dashboard: Real-time table of all active connections with operator IP, duration, and 1-click termination.

Oversight

Active PAM Console & 1-Click Killswitch

Security directors and NOC supervisors maintain live visibility over all active terminal sessions across the entire organization.

  • See connected operator name, target router IP, protocol, and session duration.
  • Instantly terminate suspicious or rogue sessions with 1 click using the emergency killswitch.
Winbox 2FA

Native Winbox & SSH 2FA via RADIUS Mule

RouterOS natively lacks built-in dynamic Two-Factor Authentication. MikroWizard solves this with an embedded RADIUS Mule daemon listening on standard RADIUS authentication ports.

  • When logging in via desktop Winbox, enter Password+TOTP (e.g. MySecret123456).
  • The Mule intercepts the MS-CHAPv2 payload, validates credentials, and confirms the 6-digit TOTP token.
RADIUS 2FA Configuration Settings
Inspect High-Res Screen

RADIUS Mule Configuration: Host IP, shared secret, and dual-layer OTP token verification rules.

Password Vault Policy Settings
Inspect High-Res Screen

Encrypted Credential Vault: Automated password rotation rules and complexity policies across device tiers.

Credential Vault

Encrypted Password Vault & Automated Rotation

Stop storing router administrative passwords in unencrypted spreadsheets. The integrated vault secures all access credentials with AES-256 encryption.

  • Automated scheduled credential rotation across thousands of routers simultaneously.
  • Zero-knowledge credential injection: operators access routers without knowing the raw root password.
Multi-Vendor

Multi-Vendor CLI Terminal Protocol Templates

While purpose-built for MikroTik RouterOS, MikroWizard's terminal engine includes dynamic protocol templates for Cisco IOS, Linux bash, VyOS, and EdgeOS.

  • Configurable prompt matchers, escape sequences, and line termination settings.
  • Unified terminal gateway experience across heterogeneous datacenter equipment.
CLI Terminal Protocol Templates Library
Inspect High-Res Screen

Protocol Template Directory: Pre-configured and custom prompt definitions for heterogeneous network devices.

Zero-Trust Ready

Secure Your Network Fleet with MikroWizard PAM

Deploy on-premises with Docker in under 5 minutes. Experience zero-client terminal access, kernel policy enforcement, and live collaboration.

Request Live Architecture Demo Explore Pricing Plans