sheet-plasticDefault configuration

circle-info

RouterOS default configuration provides a secure, production-ready setup for most networking scenarios, including firewall protection, DHCP services, and basic connectivity suitable for home offices and small businesses.

In WinBox you can apply default configuration in System -> Reset Configuration, or you can use terminal with command /system reset-configuration

The RouterOS default configuration includes essential services, security features, and network connectivity that works out-of-the-box for most common deployment scenarios.


Understanding default configuration

What gets configured automatically

Network setup:

  • Bridge interface - All ethernet ports bridged together

  • DHCP server - Automatic IP assignment for LAN clients

  • DNS resolver - Local DNS forwarding and caching

  • Default routes - Automatic gateway configuration via DHCP client

  • Network interfaces - All ports enabled and configured

Security features:

  • Firewall rules - Basic input and forward filtering

  • NAT configuration - Internet sharing via masquerade

  • Service security - Management services restricted to LAN

  • User accounts - Admin user with no password (initially)

Management services:

  • WinBox access - Graphical management interface

  • Web interface - HTTP-based configuration

  • SSH access - Secure command line access

  • MAC-Telnet - Discovery and access protocol


Fresh RouterOS installation

Initial setup procedure

After flashing RouterOS or factory reset:

Default network addressing

The default configuration uses these IP ranges:


Complete default configuration script

RouterOS v7 default configuration

This is what RouterOS applies during reset-configuration:


Customizing default configuration

Secure the default setup

Essential security modifications:

Customize network addressing

Change default IP scheme to match your requirements:


WiFi configuration (if supported)

Basic WiFi setup on devices with wireless

Guest WiFi network (optional)


Default configuration variants

Home office configuration

Optimized for home/small office use:

Branch office configuration

For connecting remote office to headquarters:


Monitoring default configuration

Verify configuration status

Monitor system logs


Backup and restore procedures

Export default configuration

Restore configuration


Troubleshooting default configuration

Common issues and solutions

Performance verification


chevron-rightShow complete secure default configurationhashtag

Default configuration best practices

Security recommendations

  1. Change default password immediately - Never leave admin account without password

  2. Disable unnecessary services - Only enable services you actually need

  3. Use strong firewall rules - Implement comprehensive filtering

  4. Enable logging - Monitor system activity and security events

  5. Regular updates - Keep RouterOS version current

Network design principles

  1. Plan IP addressing - Use consistent, documented IP schemes

  2. Implement proper segmentation - Separate guest, management, and production networks

  3. Configure redundancy - Plan for backup connectivity when possible

  4. Monitor performance - Establish baseline metrics

  5. Document configuration - Keep records of all customizations

Maintenance procedures

  1. Regular backups - Export configurations and create system backups

  2. Change monitoring - Track all configuration modifications

  3. Performance testing - Verify throughput and latency regularly

  4. Security audits - Review firewall rules and access controls

  5. Capacity planning - Monitor resource usage and plan for growth

Last updated

Was this helpful?