● LIVE· № 001 · SANITIZE EVERYTHING THAT HITS GIT: CLEANING PUBLIC REPOS FROM IDENTITY LEAKS · 2026.05.11· № 002 · IMAGEGEN-MCP: A HOMEGROWN MCP SERVER FOR BLOG COVERS · 2026.05.11· № 003 · SMART PASTE: STRIPPING TERMINAL NOISE BEFORE PASTING, WITH ONE HOTKEY · 2026.05.10· № 004 · CLAUDE CODE TEAM TELEMETRY: CENTRALIZED USAGE STATS · 2026.05.07· № 005 · CLAUDE CODE ONBOARDING GUIDE FOR NEWCOMERS · 2026.05.06· 11 POSTS · 0 DRAFTS
EN / RU
·18 MIN

MikroTik Chateau 5G R17 AX — base setup

First-boot setup, LAN / WAN, eSIM + 5G failover, WiFi, backup / restore for the Chateau 5G R17 AX on RouterOS 7.19.5. Real commands, real traps.

First-boot setup, LAN / WAN, eSIM + 5G failover, WiFi, backup / restore for the Chateau 5G R17 AX on RouterOS 7.19.5.

Step 0. Preparation

What you need:

  • WinBox x64 (download from mikrotik.com/download)
  • LTE plan app on your phone (if using LTE as the backup)
  • Offline QR scanner on your phone (the operator gives the LPA as a QR — you need the text)
  • USB-ethernet adapter (if your laptop has no dedicated ethernet port)
  • Antennas screwed onto the router (no signal without them)

Step 1. First connection via MAC

  1. Plug the laptop into LAN (any of ether2–ether5; not ether1 — that's WAN)
  2. Launch WinBox → Neighbors tab
  3. The router appears in the list; IP may be 0.0.0.0 — that's normal
  4. Click the MAC address (not the IP) → login admin, password from the sticker on the bottom
  5. If the config is already custom — back it up (see the backup section) before any changes

Step 2. Changing the LAN subnet

Default on the Chateau is 192.168.88.0/24. If an upstream device hands out the same subnet, routing silently breaks. Change to 192.168.50.0/24:

/ip address add address=192.168.50.1/24 interface=bridge
/ip address remove [find address~"^192.168.88"]
/ip pool set [find name=default-dhcp] ranges=192.168.50.10-192.168.50.254
/ip dhcp-server network set [find] address=192.168.50.0/24 gateway=192.168.50.1 dns-server=192.168.50.1
/ip dns static set [find] address=192.168.50.1

LAN clients pick up 192.168.50.x on the next DHCP renew. If you connected via MAC, your session doesn't drop.

Verify:

/ip address print

Should show 192.168.50.1/24 on bridge.

Step 3. WAN on ether1

Default config already has a DHCP client on ether1. Check:

/ip dhcp-client print detail

Status should be bound, with an IP and gateway from the ISP. For failover you'll disable automatic default-route creation so you can add the route manually with check-gateway=ping:

/ip dhcp-client set [find interface=ether1] add-default-route=no

Step 4. Activating the LTE plan eSIM

4.1. Get the LPA from LTE plan

  1. Open the LTE plan app

  2. <your operator app> → add new SIM → eSIM → data-only → Router

  3. A QR code appears. Screenshot or scan it with another phone using an offline QR scanner (so it doesn't try to open a URL)

  4. You'll get a string like:

    LPA:1$sm-v4-009-pla-gtm.pr.go-esim.com$D001-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

    One-time — never publish it.

4.2. Switch the SIM slot to eSIM

/interface lte settings set sim-slot=esim

Wait 10–15s, then:

/interface lte print detail

The SIM not present line should disappear.

4.3. Provision the profile

Split the LPA:

  • SM-DP+ address: everything between LPA:1$ and the next $
  • Matching-ID: everything after the second $
/interface/lte/esim
provision interface=lte1 sm-dp-plus=sm-v4-009-pla-gtm.pr.go-esim.com matching-id=D001-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Important: the router needs internet (via ether1) to reach the SM-DP+ server. status: resolving error → check /ping 1.1.1.1 and set DNS (/ip dns set servers=1.1.1.1,8.8.8.8).

4.4. Activate the LTE profile

/interface lte esim print

You'll see several profiles — MikroTik Connectivity test profiles (UICCID starts with 8935...) and your LTE eSIM (UICCID 8948...). Activate the LTE profile:

/interface lte esim activate number=2
/interface lte esim set-nickname number=2 nickname=LTEPlan

Verify the flag A next to LTEPlan.

Step 5. APN and LTE check

APN for <LTE ISP> is internet:

/interface lte apn set [find default=yes] apn=internet
/interface lte set lte1 apn-profiles=default

Check:

/interface lte monitor lte1 once

Expected:

  • status: running
  • current-operator: <LTE ISP>
  • imsi: starts with your country MCC
  • data-class: LTE or 5G
  • rssi closer to 0 is better (-50 dBm excellent, -100 dBm poor)
/ip address print where interface=lte1
/ping 1.1.1.1 interface=lte1 count=4

Step 6. Failover configuration

6.1. Interface list

/interface list member print where list=WAN

Should contain ether1 and lte1. If not:

/interface list member add list=WAN interface=ether1
/interface list member add list=WAN interface=lte1

6.2. Find the ISP gateway

/ip dhcp-client print detail

Field gateway=X.X.X.X.

6.3. Add the routes (recursive method)

Substitute your own gateway:

/ip dhcp-client set [find interface=ether1] add-default-route=no
/ip route add dst-address=1.1.1.1/32 gateway=192.168.88.1 scope=10 comment="recursive-probe"
/ip route add dst-address=0.0.0.0/0 gateway=1.1.1.1 distance=1 check-gateway=ping target-scope=11 comment="WAN-ether1"
/ip route add dst-address=0.0.0.0/0 gateway=lte1 distance=2 comment="WAN-lte-backup"

Logic:

  • Helper route to 1.1.1.1 goes via the ISP gateway (not default)
  • Default via 1.1.1.1 with check-gateway=ping actually pings a public IP — not just the local gw
  • Ping to 1.1.1.1 fails → route deactivates → traffic falls to LTE

6.4. Verify

/ip route print where dst-address=0.0.0.0/0 or dst-address=1.1.1.1/32

Expect:

  • A s — active recursive probe (1.1.1.1/32 via ISP gw)
  • A s — default via 1.1.1.1 (through ether1) distance=1
  • s — default via lte1 (backup) distance=2
  • D m — dynamic modem default (auto-created, leave alone)

Step 7. NAT and firewall

Default config already has masquerade:

/ip firewall nat print

Should include:

chain=srcnat action=masquerade out-interface-list=WAN

Both ether1 and lte1 are in the WAN list, so masquerade works for both automatically.

If missing:

/ip firewall nat add chain=srcnat action=masquerade out-interface-list=WAN comment="masq WAN"

Step 8. Failover test

Simulate a failure:

/interface disable ether1

Wait 15s, check:

/ip route print where dst-address=0.0.0.0/0
/ping 1.1.1.1 count=4
  • Route via 1.1.1.1 → flag I (Inactive)
  • Route via lte1 → flag A (Active)
  • Pings via LTE (TTL=53, ~30–170ms)

Return:

/interface enable ether1

After 15–30s the ether1 route becomes active again.

Step 9. WiFi 2.4 / 5 GHz and the DFS trap

Chateau is dual-band; interfaces are wifi1 (5 GHz) and wifi2 (2.4 GHz) under /interface wifi on RouterOS 7.19.5.

9.1. Basic SSID and password

/interface wifi set wifi1 ssid="MyHome-5G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="StrongPassword123"
/interface wifi set wifi2 ssid="MyHome-2G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="StrongPassword123"
/interface wifi set wifi1 disabled=no
/interface wifi set wifi2 disabled=no

Country is mandatory — without it the radio won't start:

/interface wifi set wifi1 configuration.country=<COUNTRY>
/interface wifi set wifi2 configuration.country=<COUNTRY>

9.2. The 5 GHz DFS trap

Symptoms:

  • /interface wifi print → flags MB — no R (not Running)
  • /interface wifi monitor wifi1 once → state: running, but the laptop can't see the SSID
  • Channel: 5720 MHz = DFS channel 144 (UNII-2e)

Cause: DFS channels (52–144) require 60s of silence-listening for radar before broadcast. If radar is detected — channel blocked for 30 min. During the CAC (Channel Availability Check) the Chateau shows a confusing state: monitor says "running", but clients don't see the SSID.

Quick fix — force a non-DFS channel (36 / 5180 MHz):

/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi disable wifi1
/interface wifi enable wifi1

Non-DFS 5 GHz channels for your regulatory domain (example): 36, 40, 44, 48 (UNII-1) and 149, 153, 157, 161, 165 (UNII-3). Some devices don't support UNII-3 cleanly — start with 36.

Check flag R:

/interface wifi print
# Expect: RM  or  XRM — R is the important part

9.3. Verify with clients

/interface wifi registration-table print

Lists connected clients with MAC, signal, and interface.

Step 10. Configuration backup

Two backup types — save both.

Binary (full, encrypted)

/system backup save name=full-2026-04-20 password=PASSWORD

Without password= the backup is unencrypted — contains passwords and keys in plaintext. Always use a password if the backup leaves the router.

Text export

/export file=full-2026-04-20 show-sensitive

show-sensitive includes WiFi passwords. Handle as carefully as the binary.

Download

In WinBox → Files → drag .backup and .rsc to your desktop. Keep copies on external media, cloud, and another physical device.

Restoring from backup

Scenario A: Router alive, rolling back settings.

/system backup load name=full-2026-04-20 password=PASSWORD

Reboot, settings fully restored.

Scenario B: Factory reset. Connect via MAC, decline default config, upload .backup to Files, then /system backup load.

Scenario C: New unit. A binary backup does NOT work on different hardware (tied to serial). Open the .rsc in a text editor, adjust for new hardware, and /import line by line.

Common problems

"SIM not present"

  • Did you switch the slot to eSIM? → /interface lte settings set sim-slot=esim
  • Update firmware → /system package update check-for-updates
  • Reboot → /system reboot

eSIM provision: "resolving error"

No internet on the router / DNS doesn't resolve:

/ping 1.1.1.1 count=4
/ping google.com count=4
/ip dns set servers=1.1.1.1,8.8.8.8
/ip dns cache flush

Syntax error on the provision command

  • Command split across lines — write it on one line
  • $ not escaped — use single quotes or split into sm-dp-plus=... and matching-id=...
  • install / download commands in /interface/lte/esim do not exist — correct command is provision

5 GHz WiFi: MB flag without R

DFS channel + CAC scan in progress. Force non-DFS:

/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi disable wifi1
/interface wifi enable wifi1

Tab autocomplete doesn't work in the WinBox terminal

Switch to SSH:

ssh [email protected]

Tab works normally in SSH.

Command cheat sheet

Full pack for a from-scratch re-setup:

# 0. Backup current state
/system backup save name=before-setup password=pwd
/export file=before-setup show-sensitive
 
# 1. Change LAN subnet
/ip address add address=192.168.50.1/24 interface=bridge
/ip address remove [find address~"^192.168.88"]
/ip pool set [find name=default-dhcp] ranges=192.168.50.10-192.168.50.254
/ip dhcp-server network set [find] address=192.168.50.0/24 gateway=192.168.50.1 dns-server=192.168.50.1
/ip dns static set [find] address=192.168.50.1
 
# 2. Switch to eSIM
/interface lte settings set sim-slot=esim
 
# 3. Provision the eSIM
/interface/lte/esim
provision interface=lte1 sm-dp-plus=SERVER matching-id=CODE
 
# 4. Activate
/interface lte esim print
/interface lte esim activate number=N
 
# 5. APN
/interface lte apn set [find default=yes] apn=internet
/interface lte set lte1 apn-profiles=default
 
# 6. Failover
/ip dhcp-client set [find interface=ether1] add-default-route=no
/ip route add dst-address=1.1.1.1/32 gateway=GATEWAY-ISP scope=10 comment="recursive-probe"
/ip route add dst-address=0.0.0.0/0 gateway=1.1.1.1 distance=1 check-gateway=ping target-scope=11 comment="WAN-ether1"
/ip route add dst-address=0.0.0.0/0 gateway=lte1 distance=2 comment="WAN-lte-backup"
 
# 7. WiFi (force non-DFS channel 36)
/interface wifi set wifi1 configuration.country=<COUNTRY> ssid="MyHome-5G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="WiFiPassword"
/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi set wifi2 configuration.country=<COUNTRY> ssid="MyHome-2G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="WiFiPassword"
/interface wifi enable wifi1
/interface wifi enable wifi2
 
# 8. Final backup
/system backup save name=working-config password=pwd
/export file=working-config show-sensitive

RouterOS: 7.19.5 · Hardware: Chateau 5G R17 AX