● LIVE· № 001 · SANITIZE EVERYTHING THAT HITS GIT: CLEANING PUBLIC REPOS FROM IDENTITY LEAKS · 2026.05.11· № 002 · IMAGEGEN-MCP: A HOMEGROWN MCP SERVER FOR BLOG COVERS · 2026.05.11· № 003 · SMART PASTE: STRIPPING TERMINAL NOISE BEFORE PASTING, WITH ONE HOTKEY · 2026.05.10· № 004 · CLAUDE CODE TEAM TELEMETRY: CENTRALIZED USAGE STATS · 2026.05.07· № 005 · CLAUDE CODE ONBOARDING GUIDE FOR NEWCOMERS · 2026.05.06· 11 POSTS · 0 DRAFTS
EN / RU
·9 MIN

MikroTik Chateau 5G R17 AX — home setup notes

Real-world notes from setting up a MikroTik Chateau 5G R17 AX as a home router with 5G failover, remote access, and a dedicated corporate-VPN SSID. Lessons from rakes I stepped on.

Notes from setting up my MikroTik Chateau 5G R17 AX (board S53UG+5HaxD2HaxD&RG650E-EU, Quectel RG650E-EU modem, RouterOS 7.19.5) as a home router with 5G failover, remote access, and a dedicated corporate-VPN SSID. Everything here is based on what I actually ran; lessons are from rakes I stepped on.

Hardware snapshot

ParameterValue
ModelMikroTik Chateau 5G R17 AX
BoardS53UG+5HaxD2HaxD&RG650E-EU
ModemQuectel RG650E-EU
RouterOS7.19.5
Primary WANether1 (DHCP from upstream)
Backup WANlte1 + eSIM LTE plan
LAN subnet192.168.50.0/24 (changed from default)
APNinternet
Operator<LTE ISP>

Goals for the setup

  • Primary internet via cable on ether1
  • Automatic switchover to eSIM (5G) when ether1 fails
  • Automatic return to ether1 when it recovers
  • Remote access to the home network even when the router sits behind CGNAT
  • A separate SSID that tunnels everything through corporate GlobalProtect, so I don't have to launch GP on each device

The companion posts

  • Base MikroTik setup — first boot, LAN subnet, WAN on ether1, LTE plan eSIM, failover ether1 ↔ LTE, NAT, WiFi 2.4 / 5 GHz and the DFS trap, backup / restore.
  • Back To Home VPN (MikroTik cloud) — free built-in WireGuard-based remote access that works through CGNAT. Enable, add peers, generate QR for the iOS / Android app.
  • Hardening + extensions — security, WAN-flap alerting via Telegram, power-loss behavior, DNS over HTTPS, RouterOS upgrade strategy.

Lessons learned the hard way

All the rakes from this project in one place. If I come back to any of it later, I start here.

  1. SIM-slot selection is NOT /interface lte set lte1 sim-slot=.... Use /interface lte settings set sim-slot=esim. Values are sim / esim, not up / down / auto.
  2. The eSIM provision command takes separate params, not a whole LPA string. Split LPA:1$smdp.XXX$MATCHING-ID into sm-dp-plus=smdp.XXX and matching-id=MATCHING-ID.
  3. Don't use \$ in double quotes for LPA strings. Use single quotes, or no quotes (value has no spaces).
  4. WinBox terminal truncates long strings on paste. Use SSH (ssh admin@<router>) from git bash.
  5. provision needs a working internet connection. Without it → resolving error.
  6. Subnet conflicts silently break everything. Default Chateau LAN is 192.168.88.0/24 — if your upstream is on the same subnet, routing breaks. First move: change the LAN subnet.
  7. Tab-Tab in the terminal lists available commands and parameters. Use it instead of guessing.
  8. LTE plan eSIM is obtained through the phone app (<your operator app> → add new SIM → eSIM → data-only → Router). MultiSIM is free, number of extras depends on plan.
  9. The Chateau ships with MikroTik Connectivity test eSIMs — don't accidentally activate them; check UICCID before pressing activate.
  10. Recursive routing beats check-gateway against the ISP gateway for failover. Ping 1.1.1.1 through the ISP gateway — failover fires even if the gateway is alive but the ISP's internet is down.
  11. WinBox MAC connection doesn't drop when IPs change. Connect via MAC first; then safely edit addresses.
  12. 5 GHz DFS channels trap. monitor says state: running but clients can't see the SSID. Force a non-DFS channel (36 / 5180 MHz) until you know what you're doing.
  13. Back To Home VPN lives under /ip cloud as a property, not a submenu. Users live under /ip cloud back-to-home-user (singular). Don't mix / and spaces in command paths.
  14. Openconnect + --background + expect = SIGHUP death a few seconds after auth. Run openconnect in the foreground under systemd Type=simple.
  15. Palo Alto IP pools differ by client OS. --os=mac-intel can get you out of an ACL block that bites --os=linux. Not HIP spoofing — just the OS fingerprint.
  16. UID-based ip rule policy routing breaks Node.js DNS (c-ares). Use dnsmasq server=IP@interface instead to steer specific queries.
  17. chattr +i /etc/resolv.conf is how you stop vpnc-script from trashing the Pi's own DNS on every reconnect.

RouterOS: 7.19.5 · Hardware: Chateau 5G R17 AX (S53UG+5HaxD2HaxD&RG650E-EU)