MikroTik – Advanced Course (MT2)

Networking, MikroTik

This advanced course focuses on network defense using perimeter traffic filtering with a stateful firewall organized by zones (internal, Internet, DMZ). You will learn configuration of packet filtering, policy placement toward the ISP, and practical perimeter protection techniques.

The course also covers advanced firewall features such as NAT types and connection tracking, remote access via IPsec and WireGuard, controller-managed Wi‑Fi (CAPsMAN) and hands-on labs to practice real-world network and wireless management scenarios.

THIS TRAINING COURSE WILL HELP YOU:

  • Deepen skills in zone-based stateful firewall design
  • Use advanced packet filtering and matching
  • Configure CAPsMAN for controller-managed Wi-Fi
  • Apply knowledge in practical lab scenarios

WHO SHOULD ATTEND?

  • Network administrators seeking advanced security skills
  • Technicians working with MikroTik routers and switches
  • IT pros focusing on Wi-Fi deployment and optimization
  • Specialists responsible for network security and performance

COURSE LOCATION AND AVAILABLE DATES



This course is delivered in person only in our fully equipped classrooms. All necessary equipment and the prepared training environment are provided.

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • IPv4 protocol and routing
    1. Brief IPv4 recap
    2. Lab: static routing
    3. Basics of dynamic routing (distance-vector vs link-state, metrics, AD)
    4. Passive interfaces, authentication
    5. Lab: dynamic routing (RIP, OSPF)
  • MikroTik Firewall (IPv4)
    1. Filter, chains: input, forward, output, user chains
    2. Rule matching by interface / L2 / L3 / L4
    3. Connection states: new, established, related, invalid
    4. Conntrack and connection table
    5. Actions: accept, drop, reject, jump, log
    6. Rate limiting
    7. Address lists
    8. Lab: practical demo of two- and three-zone firewall
    9. DDoS protection
    10. Port knocking
  • NAT for IPv4
    1. NAT principles: SNAT, DNAT, static, port mapping
    2. SNAT vs masquerade
    3. DNAT, port mapping/forwarding
    4. Redirect, transparent DNS proxy
    5. Lab: practical NAT demo
  • VPN - IPsec
    1. Site-to-site and remote-access VPNs
    2. Encryption, authentication, integrity, anti-replay
    3. ESP/AH protocols, transport vs tunnel mode
    4. Tunnel negotiation (IKE, ISAKMP, SAs, ...)
    5. Lab: site-to-site IPsec VPN
  • WireGuard
    1. Authentication and key exchange
    2. Defining peers
    3. Distributing client configuration
    4. Site-to-site setups
    5. Remote-access (back-to-home)
    6. Practical lab
  • HotSpot
    1. Web-based network access (captive portal)
    2. Login methods including RADIUS
    3. Walled garden (allowed pages without login)
    4. Custom login page
    5. User limits (rate / size / time)
    6. HotSpot status, logging, accounting
    7. Lab: HotSpot practical exercise
  • CAPsMAN
    1. Wi‑Fi site survey
    2. Autonomous vs controller-managed Wi‑Fi
    3. CAPsMAN requirements and limitations
    4. CAPsMAN and CAP roles and communication
    5. Secondary SSID for guest access
    6. Rate limiting for wireless users
    7. Local vs master forwarding modes
    8. Monitoring and maintenance of CAPsMAN
    9. Lab: CAPsMAN practical exercise
Prerequisites:
Basic familiarity with TCP/IP network security and MT1-level MikroTik knowledge.
Recommended previous course:
MikroTik – Basic Course (MT1)
Schedule:
1 day (9:00-17:00)
Price per person:
288.00 € ( 348.48 € incl. 21% VAT)

Training and learning environment