First-boot setup, LAN / WAN, eSIM + 5G failover, WiFi, backup / restore for the Chateau 5G R17 AX on RouterOS 7.19.5.
Step 0. Preparation
What you need:
- WinBox x64 (download from mikrotik.com/download)
- LTE plan app on your phone (if using LTE as the backup)
- Offline QR scanner on your phone (the operator gives the LPA as a QR — you need the text)
- USB-ethernet adapter (if your laptop has no dedicated ethernet port)
- Antennas screwed onto the router (no signal without them)
Step 1. First connection via MAC
- Plug the laptop into LAN (any of
ether2–ether5; notether1— that's WAN) - Launch WinBox → Neighbors tab
- The router appears in the list; IP may be
0.0.0.0— that's normal - Click the MAC address (not the IP) → login
admin, password from the sticker on the bottom - If the config is already custom — back it up (see the backup section) before any changes
Step 2. Changing the LAN subnet
Default on the Chateau is 192.168.88.0/24. If an upstream device hands out the same subnet, routing silently breaks. Change to 192.168.50.0/24:
/ip address add address=192.168.50.1/24 interface=bridge
/ip address remove [find address~"^192.168.88"]
/ip pool set [find name=default-dhcp] ranges=192.168.50.10-192.168.50.254
/ip dhcp-server network set [find] address=192.168.50.0/24 gateway=192.168.50.1 dns-server=192.168.50.1
/ip dns static set [find] address=192.168.50.1LAN clients pick up 192.168.50.x on the next DHCP renew. If you connected via MAC, your session doesn't drop.
Verify:
/ip address printShould show 192.168.50.1/24 on bridge.
Step 3. WAN on ether1
Default config already has a DHCP client on ether1. Check:
/ip dhcp-client print detailStatus should be bound, with an IP and gateway from the ISP. For failover you'll disable automatic default-route creation so you can add the route manually with check-gateway=ping:
/ip dhcp-client set [find interface=ether1] add-default-route=noStep 4. Activating the LTE plan eSIM
4.1. Get the LPA from LTE plan
-
Open the LTE plan app
-
<your operator app>→ add new SIM → eSIM → data-only → Router -
A QR code appears. Screenshot or scan it with another phone using an offline QR scanner (so it doesn't try to open a URL)
-
You'll get a string like:
LPA:1$sm-v4-009-pla-gtm.pr.go-esim.com$D001-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXOne-time — never publish it.
4.2. Switch the SIM slot to eSIM
/interface lte settings set sim-slot=esimWait 10–15s, then:
/interface lte print detailThe SIM not present line should disappear.
4.3. Provision the profile
Split the LPA:
- SM-DP+ address: everything between
LPA:1$and the next$ - Matching-ID: everything after the second
$
/interface/lte/esim
provision interface=lte1 sm-dp-plus=sm-v4-009-pla-gtm.pr.go-esim.com matching-id=D001-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXImportant: the router needs internet (via ether1) to reach the SM-DP+ server. status: resolving error → check /ping 1.1.1.1 and set DNS (/ip dns set servers=1.1.1.1,8.8.8.8).
4.4. Activate the LTE profile
/interface lte esim printYou'll see several profiles — MikroTik Connectivity test profiles (UICCID starts with 8935...) and your LTE eSIM (UICCID 8948...). Activate the LTE profile:
/interface lte esim activate number=2
/interface lte esim set-nickname number=2 nickname=LTEPlanVerify the flag A next to LTEPlan.
Step 5. APN and LTE check
APN for <LTE ISP> is internet:
/interface lte apn set [find default=yes] apn=internet
/interface lte set lte1 apn-profiles=defaultCheck:
/interface lte monitor lte1 onceExpected:
status: runningcurrent-operator: <LTE ISP>imsi:starts with your country MCCdata-class: LTEor5Grssicloser to 0 is better (-50 dBm excellent, -100 dBm poor)
/ip address print where interface=lte1
/ping 1.1.1.1 interface=lte1 count=4Step 6. Failover configuration
6.1. Interface list
/interface list member print where list=WANShould contain ether1 and lte1. If not:
/interface list member add list=WAN interface=ether1
/interface list member add list=WAN interface=lte16.2. Find the ISP gateway
/ip dhcp-client print detailField gateway=X.X.X.X.
6.3. Add the routes (recursive method)
Substitute your own gateway:
/ip dhcp-client set [find interface=ether1] add-default-route=no
/ip route add dst-address=1.1.1.1/32 gateway=192.168.88.1 scope=10 comment="recursive-probe"
/ip route add dst-address=0.0.0.0/0 gateway=1.1.1.1 distance=1 check-gateway=ping target-scope=11 comment="WAN-ether1"
/ip route add dst-address=0.0.0.0/0 gateway=lte1 distance=2 comment="WAN-lte-backup"Logic:
- Helper route to
1.1.1.1goes via the ISP gateway (not default) - Default via
1.1.1.1withcheck-gateway=pingactually pings a public IP — not just the local gw - Ping to
1.1.1.1fails → route deactivates → traffic falls to LTE
6.4. Verify
/ip route print where dst-address=0.0.0.0/0 or dst-address=1.1.1.1/32Expect:
A s— active recursive probe (1.1.1.1/32via ISP gw)A s— default via1.1.1.1(throughether1) distance=1s— default vialte1(backup) distance=2D m— dynamic modem default (auto-created, leave alone)
Step 7. NAT and firewall
Default config already has masquerade:
/ip firewall nat printShould include:
chain=srcnat action=masquerade out-interface-list=WANBoth ether1 and lte1 are in the WAN list, so masquerade works for both automatically.
If missing:
/ip firewall nat add chain=srcnat action=masquerade out-interface-list=WAN comment="masq WAN"Step 8. Failover test
Simulate a failure:
/interface disable ether1Wait 15s, check:
/ip route print where dst-address=0.0.0.0/0
/ping 1.1.1.1 count=4- Route via
1.1.1.1→ flagI(Inactive) - Route via
lte1→ flagA(Active) - Pings via LTE (TTL=53, ~30–170ms)
Return:
/interface enable ether1After 15–30s the ether1 route becomes active again.
Step 9. WiFi 2.4 / 5 GHz and the DFS trap
Chateau is dual-band; interfaces are wifi1 (5 GHz) and wifi2 (2.4 GHz) under /interface wifi on RouterOS 7.19.5.
9.1. Basic SSID and password
/interface wifi set wifi1 ssid="MyHome-5G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="StrongPassword123"
/interface wifi set wifi2 ssid="MyHome-2G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="StrongPassword123"
/interface wifi set wifi1 disabled=no
/interface wifi set wifi2 disabled=noCountry is mandatory — without it the radio won't start:
/interface wifi set wifi1 configuration.country=<COUNTRY>
/interface wifi set wifi2 configuration.country=<COUNTRY>9.2. The 5 GHz DFS trap
Symptoms:
/interface wifi print→ flagsMB— noR(not Running)/interface wifi monitor wifi1 once→state: running, but the laptop can't see the SSID- Channel: 5720 MHz = DFS channel 144 (UNII-2e)
Cause: DFS channels (52–144) require 60s of silence-listening for radar before broadcast. If radar is detected — channel blocked for 30 min. During the CAC (Channel Availability Check) the Chateau shows a confusing state: monitor says "running", but clients don't see the SSID.
Quick fix — force a non-DFS channel (36 / 5180 MHz):
/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi disable wifi1
/interface wifi enable wifi1Non-DFS 5 GHz channels for your regulatory domain (example): 36, 40, 44, 48 (UNII-1) and 149, 153, 157, 161, 165 (UNII-3). Some devices don't support UNII-3 cleanly — start with 36.
Check flag R:
/interface wifi print
# Expect: RM or XRM — R is the important part9.3. Verify with clients
/interface wifi registration-table printLists connected clients with MAC, signal, and interface.
Step 10. Configuration backup
Two backup types — save both.
Binary (full, encrypted)
/system backup save name=full-2026-04-20 password=PASSWORDWithout password= the backup is unencrypted — contains passwords and keys in plaintext. Always use a password if the backup leaves the router.
Text export
/export file=full-2026-04-20 show-sensitiveshow-sensitive includes WiFi passwords. Handle as carefully as the binary.
Download
In WinBox → Files → drag .backup and .rsc to your desktop. Keep copies on external media, cloud, and another physical device.
Restoring from backup
Scenario A: Router alive, rolling back settings.
/system backup load name=full-2026-04-20 password=PASSWORDReboot, settings fully restored.
Scenario B: Factory reset. Connect via MAC, decline default config, upload .backup to Files, then /system backup load.
Scenario C: New unit. A binary backup does NOT work on different hardware (tied to serial). Open the .rsc in a text editor, adjust for new hardware, and /import line by line.
Common problems
"SIM not present"
- Did you switch the slot to eSIM? →
/interface lte settings set sim-slot=esim - Update firmware →
/system package update check-for-updates - Reboot →
/system reboot
eSIM provision: "resolving error"
No internet on the router / DNS doesn't resolve:
/ping 1.1.1.1 count=4
/ping google.com count=4
/ip dns set servers=1.1.1.1,8.8.8.8
/ip dns cache flushSyntax error on the provision command
- Command split across lines — write it on one line
$not escaped — use single quotes or split intosm-dp-plus=...andmatching-id=...install/downloadcommands in/interface/lte/esimdo not exist — correct command isprovision
5 GHz WiFi: MB flag without R
DFS channel + CAC scan in progress. Force non-DFS:
/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi disable wifi1
/interface wifi enable wifi1Tab autocomplete doesn't work in the WinBox terminal
Switch to SSH:
ssh [email protected]Tab works normally in SSH.
Command cheat sheet
Full pack for a from-scratch re-setup:
# 0. Backup current state
/system backup save name=before-setup password=pwd
/export file=before-setup show-sensitive
# 1. Change LAN subnet
/ip address add address=192.168.50.1/24 interface=bridge
/ip address remove [find address~"^192.168.88"]
/ip pool set [find name=default-dhcp] ranges=192.168.50.10-192.168.50.254
/ip dhcp-server network set [find] address=192.168.50.0/24 gateway=192.168.50.1 dns-server=192.168.50.1
/ip dns static set [find] address=192.168.50.1
# 2. Switch to eSIM
/interface lte settings set sim-slot=esim
# 3. Provision the eSIM
/interface/lte/esim
provision interface=lte1 sm-dp-plus=SERVER matching-id=CODE
# 4. Activate
/interface lte esim print
/interface lte esim activate number=N
# 5. APN
/interface lte apn set [find default=yes] apn=internet
/interface lte set lte1 apn-profiles=default
# 6. Failover
/ip dhcp-client set [find interface=ether1] add-default-route=no
/ip route add dst-address=1.1.1.1/32 gateway=GATEWAY-ISP scope=10 comment="recursive-probe"
/ip route add dst-address=0.0.0.0/0 gateway=1.1.1.1 distance=1 check-gateway=ping target-scope=11 comment="WAN-ether1"
/ip route add dst-address=0.0.0.0/0 gateway=lte1 distance=2 comment="WAN-lte-backup"
# 7. WiFi (force non-DFS channel 36)
/interface wifi set wifi1 configuration.country=<COUNTRY> ssid="MyHome-5G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="WiFiPassword"
/interface wifi set wifi1 channel.frequency=5180 channel.width=20/40/80mhz
/interface wifi set wifi2 configuration.country=<COUNTRY> ssid="MyHome-2G" security.authentication-types=wpa2-psk,wpa3-psk security.passphrase="WiFiPassword"
/interface wifi enable wifi1
/interface wifi enable wifi2
# 8. Final backup
/system backup save name=working-config password=pwd
/export file=working-config show-sensitiveRouterOS: 7.19.5 · Hardware: Chateau 5G R17 AX
