# winbox

一个小实用程序，允许使用快速简单的GUI管理MikroTik RouterOS

&#x20;       Winbox是一个小实用程序，允许使用快速简单的GUI管理MikroTik RouterOS。它是一个原生的Win32二进制文件，但可以使用Wine 在**Linux**和**MacOS（OSX）**&#x4E0A;运行。所有Winbox接口函数尽可能接近镜像控制台功能，这就是手册中没有Winbox部分的原因。winbox无法实现某些高级和系统关键配置，例如Winbox更新日志界面上的MAC地址更改

下载地址： （winbox）

中国CDN

32位： <http://cdn.gaohou.net/winbox/winbox.exe>

64位： <http://cdn.gaohou.net/winbox/winbox64.exe>

官方下载

32位 <https://mt.lv/winbox>

64位 <https://mt.lv/winbox64>

介绍

![](/files/-LYdBmUnRgPBtv3OUSzR)

![](/files/-LYdBpX-v1PvBr5vAwOU)


# Winbox for win

RouterOS v5 使用旧版本 下载地址

{% file src="/files/-L\_2qj-LnCGBjYyPVMlN" %}
winbox v2.2.18
{% endfile %}

下载地址：&#x20;

官方下载

32位 <https://mt.lv/winbox>

64位 <https://mt.lv/winbox64>

下载地址： （winbox v2.2.18）

#### 中国CDN <http://cdn.gaohou.net/winbox2.exe>

![](/files/-L_2rFsh7dmvRxhjkZl-)


# Winbox for Mac

## 利用Wine手动创建 Winbox for Mac

新版winbox 64位 在MacBook上的使用方法

更新：这现在也适用于 Apple M1 芯片！

{% embed url="<https://forum.mikrotik.com/viewtopic.php?f=2&t=152795&p=754980#p754824>" %}

```
如果您以前使用过 Wine，我们建议您先删除以前的 Wine 应用程序和主文件夹中的 Wine 设置目录：

rm -rf /Applications/Wine*
rm -rf ~/.wine/

运行 Winbox64.exe 的步骤如下是必须的。
从https://github.com/Gcenx/macOS_Wine_builds/releases

安装 Wine， 并确保您已从 MikroTik 下载页面下载了 winbox64.exe 可执行文件。 
安装过程中，必须勾选“64 bit support”（默认不勾选）。 
在 macOS 终端中，
确保您设置为像这样使用 ZSH 作为新 shell（并在此命令之后重新启动终端）： chsh -s /bin/zsh

编辑您的 zprofile 文件以添加环境变量，将 wine64 命令指向 Wine Staging 的正确安装路径：

nano ~/.zprofile

该文件应如下所示（确保您的路径在此处正确）：

export PATH="/Applications/ Wine Staging.app/Contents/Resources/wine/bin:$PATH"
export FREETYPE_PROPERTIES="truetype:interpreter-version=35"
export DYLD_FALLBACK_LIBRARY_PATH="/usr/lib:/opt/X11/lib:$DYLD_FALLBACK_LIBRARY_PATH"

重启（退出并重新打开）您的 macOS 终端
使用 wine64 启动 Winbox64，如下所示：

wine64 "/Applications/winbox64.exe"

或只需双击 Winbox64.exe 文件并选择使用 Wine 打开
```

## winbox-mac

winbox-mac 是[MikroTik Winbox 与](https://mikrotik.com/)[Wine](https://www.winehq.org/)捆绑到 macOS 应用程序中。Wine 由[Gcenx](https://github.com/Gcenx)编译，具有最少的依赖项。图标由[Lucas di Lucca](https://github.com/lucasdelucca)提供。这不是[MikroTik](https://mikrotik.com/)的官方版本，与 Mikrotik 没有任何关系。

{% embed url="<https://github.com/nrlquaker/winbox-mac>" %}

<figure><img src="/files/itY8rxAeCrNFhjMw5cs3" alt=""><figcaption></figcaption></figure>

## Crossover (试用14天)

{% embed url="<https://www.codeweavers.com/crossover/>" %}

Mac 和 MikroTik 粉 必备！特别适合Mac m1系列

由于当前没有用于macOS的ARM Wine版本，因此无法在基于M1处理器的Apple设备上使用。您可以尝试使用Crossover软件，它将在Rosetta2仿真模式下运行Winbox。

CrossOver是多款由CodeWeavers开发的商业及授权软件的合称，它们通过使用兼容层来允许基于Windows的软件在Linux、macOS及Chrome OS系统中运行。这套程序包括CrossOver Mac, CrossOver Linux, CrossOver Chrome OS Beta。

![](/files/-MSR7nmbJr_KLewWfmL2)

## Whiskey 适用于Apple Silicon

基于 macOS Sonoma 构建,只需几分钟即可完成安装 Whisky 并开始使用winbox.

Whisky <https://getwhisky.app/>

<figure><img src="/files/jOvgkgdgmB8mN5rSQQeN" alt=""><figcaption></figcaption></figure>


# Winbox fo Linux

Winbox 是一个小型实用程序，允许使用快速简单的 GUI 管理 MikroTik RouterOS。

Snap 包含 Wine 运行时和 winbox 客户端。

GitHub - panaceya/winbox: Snap package with winbox from MikroTik

<https://github.com/panaceya/winbox>

{% embed url="<https://github.com/panaceya/winbox>" %}

<figure><img src="/files/itY8rxAeCrNFhjMw5cs3" alt=""><figcaption></figcaption></figure>


# WinBox for IOS

适用于iOS的Winbox app

![](/files/-LaSeX9eZW6Ru7AoQIs-)

####

1. Menu 1.1. Removed firmware update button from main menu 1.2. Added option to disable internet detect by tapping row
2. Advanced menu 2.1. Added logic to delete files under "Files"
3. Settings 3.1. Added option to reset master password which wipes all current saved addresses 3.2. Added option to export saved addresses 3.3. Added option to import saved addresses
4. Login 4.1. Removed need to re-enter master password to access saved addresses if it has been entered through Settings already 4.2. Fixed issue with showing error message multiple times when failing to import WBX file
5. Quick setup 5.1. Fixed issue with some options reverting back when changed and layout not updating accordingly
6. Stability and performance improvements

**下载地址：**

![](/files/-LaSf6sQ7RN5sdnBheFW)

<https://itunes.apple.com/app/id1323064830>

![](/files/-M-pBRZMT-nQoU4VxCNy)


# WinBox for Android

RouterOS的配置工具  Android 版

![](/files/-LaSeX9eZW6Ru7AoQIs-)

MikroTik RouterOS是RouterBOARD和CCR设备的操作系统。

RouterOS为您的网络提供所有核心功能 - 路由，防火墙，带宽管理，无线接入点，回程链路，热点网关，VPN服务器等。

使用MikroTik智能手机应用程序在现场配置您的路由器，或为您的MikroTik家庭接入点应用最基本的初始设置。

新路由器上的默认用户名：admin。通常没有默认密码（留空）。

要求：运行RouterOS v6或更新版本的MikroTik路由器。

**平台下载：**

![](/files/-LaSfI0PquUd3lXA6dbB)

<https://play.google.com/store/apps/details?id=com.mikrotik.android.tikapp>

**文件下载：**

V1.3.10（2020.02.06）

中国CDN下载： <http://cdn.gaohou.net/com.mikrotik.android.tikapp_2020-02-06.apk>&#x20;

![](/files/-M-pADccMcOdB27p2sKo)

{% file src="/files/-MJ9xUSth2FAJHygBpen" %}


# 二次登录防火墙

> /ip firewall address-list add address=10.0.0.0/8 list=login&#x20;
>
> /ip firewall address-list add address=172.16.0.0/12 list=login&#x20;
>
> /ip firewall address-list add address=192.168.0.0/16 list=login&#x20;
>
> /ip firewall mangle add chain=input protocol=tcp dst-port=8888 action=add-src-to-address-list address-list=login address-list-timeout=30m comment=login&#x20;
>
> /ip firewall filter add chain=input protocol=udp dst-port=53 src-address-list=!login action=drop comment=login
>
> /ip firewall filter add chain=input protocol=tcp dst-port=8728,8729,21,22,23,53,80,2000,8291 src-address-list=!login action=drop comment=login

> 上面的脚本，能修改的地方就是8888端口。然后导入脚本， 登陆winbox先加端口8888登陆一次， 就可以用WINBOX默认端口登陆了

<figure><img src="/files/SIp3PGzfrDbXgSgo6zCX" alt=""><figcaption></figcaption></figure>


# 官方设备内置防火墙

注意！不要远程使用，会被阻拦在外面！建议在本地可控的设备上使用

高能警告！不了解不要直接远程导入使用.

```
# by RouterOS 6.44.3
/ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
/ip firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
/ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
/ip firewall filter add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
/ip firewall filter add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec  
/ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
/ip firewall filter add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
/ip firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
/ip firewall filter add action=drop chain=forward comment="defconf:  drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
```

![](/files/-LstWs46uhhEquYKDNDA)


# ROS小白变大神系列

![](/files/-M4CP8MIv5ziJgoVBw8X)

链接地址： <https://www.youtube.com/playlist?list=PLfLlxfKElwNZ2lulhX6I-5SGrbZTMPJh8>

> 如果打不开，说明某些地区需要翻墙，请自备梯子！


# 从零开始学RouterOS系列

![](/files/-M4CZwEuR8JbYfPB4DHO)

MikrotikRouterOS简介--从零开始学RouterOS系列00

<https://zhuanlan.zhihu.com/p/75774030>

设置LAN和DHCP--从零开始学RouterOS系列01

&#x20;<https://zhuanlan.zhihu.com/p/76060938>

全系列地址 <https://zhuanlan.zhihu.com/c_1139496904965607424>


# 技术支持

最新的技术文档 <https://help.mikrotik.com/docs>

官方论坛 <https://forum.mikrotik.com/>


# RouterOS v7 翻墙策略

一个设备完成翻墙，不需要其他设备辅助，严格区分国内国外，不产生冲突，v7系统稍微不同，总体一样

```c
// Some code

#其中 gateway=192.168.89.1 为服务器vpn的网关 自行改对应的
#dns static和routing rule   自行按需添加即可
#

/interface sstp-client
add connect-to=gh.run disabled=no name=sstp-vpn profile=default-encryption \
    user=gh

/routing table
add disabled=no fib name=gfw

/ip route
add check-gateway=ping disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
    192.168.89.1 pref-src="" routing-table=gfw scope=30 suppress-hw-offload=\
    no target-scope=10


/ip dns static
add forward-to=8.8.8.8 regexp=www.google.com type=FWD
add forward-to=8.8.8.8 regexp=www.gooe.com type=FWD
add forward-to=8.8.8.8 regexp=www.gle.com type=FWD

/routing rule
add action=lookup comment=dns disabled=no dst-address=8.8.0.0/16 table=gfw
add action=lookup disabled=no dst-address=34.83.0.0/16 table=gfw
add action=lookup comment=ip disabled=no dst-address=163.171.0.0/16 table=gfw
add action=lookup comment=ip disabled=no dst-address=218.75.0.0/16 table=gfw
```

### 最终效果：

<figure><img src="/files/1fBKNIVBTLWK8zeg0QVm" alt=""><figcaption></figcaption></figure>


# 相关策略包和软件

{% file src="/files/-MHvisaaMencvlCvAUWh" %}


# ip

收集的一些和ip相关的工具

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>中国ip地址列表</strong></td><td><a href="http://www.tcp5.com/">http://www.tcp5.com</a></td><td>ros路由表格式table</td></tr><tr><td><strong>IP段地址查询</strong></td><td></td><td>通过ip查IP段</td></tr><tr><td><strong>IP 地址查询</strong> </td><td><a href="https://nb5p.github.io/MyIP">nb5p.github.io/MyIP</a></td><td>多个源头查询ip</td></tr><tr><td><strong>Chinaip by IPIP.NET</strong></td><td><a href="https://www.iwik.org/ipcountry/mikrotik/CN">https://www.iwik.org</a></td><td>每月更新,地址列表格式list</td></tr><tr><td><strong>IP地址查询</strong></td><td><a href="https://www.whatismyip.com.tw/">www.whatismyip.com.tw</a></td><td>简约ip查询</td></tr><tr><td><strong>BGP Toolkit</strong></td><td><a href="https://bgp.he.net">https://bgp.he.net</a></td><td>查询BGP的AS号</td></tr><tr><td><strong>IP 地址及归属地</strong></td><td><a href="https://ip.skk.moe">https://ip.skk.moe</a></td><td>测试 CDN 命中节点</td></tr></tbody></table>


# Google DDNS

了解动态 DNS - Google Domains帮助&#x20;

<https://support.google.com/domains/answer/6147083>

获取当前外网IP&#x20;

<https://domains.google.com/checkip>

```bash
/tool fetch mode=https url="https://user:password@domains.google.com/nic/update?hostname=ddns.le.com&myip=43.12.14.3" http-method=post
```

\[RouterOS] 更新 Google Domains DDNS script – RAYKUO'S BLOG&#x20;

<https://blog.ladsai.com/mikrotik-routeros-%E6%9B%B4%E6%96%B0-google-domains-ddns-script.html>


# Cloudflare

cloudflare官方案例文档使用脚本更新案列详解【DDNS动态域名解析】<https://www.cnblogs.com/uwiu/p/15794986.html>


# MikroTik脚本生成器

下载地址

Ver2.12:  文件大小：6.96 MB 上传时间：2021-02-04

{% file src="/files/3a9IkLZpsF3K88SWGFYM" %}

\
解压密码:1234

\
md5:9b2beef025f8cfdbefcf403147ac8892 (压缩包的MD5)


# NAT

NAT类型简介

Full cone NAT： 即著名的一对一（one-to-one）NAT。一旦一个内部地址（iAddr:port1）映射到外部地址（eAddr:port2），所有发自iAddr:port1的包都经由eAddr:port2向外发送。任意外部主机都能通过给eAddr:port2发包到达iAddr:port1。

Address-Restricted cone NAT： 限制地址，即只接收曾经发送到对端的IP地址来的数据包。一旦一个内部地址（iAddr:port1）映射到外部地址（eAddr:port2），所有发自iAddr:port1的包都经由eAddr:port2向外发送。任意外部主机（hostAddr:any）都能通过给eAddr:port2发包到达iAddr:port1的前提是：iAddr:port1之前发送过包到hostAddr:any. "any"也就是说端口不受限制。

Port-Restricted cone NAT： 类似受限制锥形NAT（Restricted cone NAT），但是还有端口限制。一旦一个内部地址（iAddr:port1）映射到外部地址（eAddr:port2），所有发自iAddr:port1的包都经由eAddr:port2向外发送。一个外部主机（hostAddr:port3）能够发包到达iAddr:port1的前提是：iAddr:port1之前发送过包到hostAddr:port3。

Symmetric NAT（对称NAT）： 每一个来自相同内部IP与port的请求到一个特定目的地的IP地址和端口，映射到一个独特的外部来源的IP地址和端口。同一个内部主机发出一个信息包到不同的目的端，不同的映射使用 外部主机收到了一封包从一个内部主机可以送一封包回来。


