Annoyances with RESET buttons (wsAP, crs-318, crs-328 )

Ok, I've been a long-time user of Mikrotik RouterOS, from the very beginning (thanks!). I wish the company success. I've got a whole host of different generations of Routerboards, say: CRS-328, wsAP ac lite (mips-be), and now the newer wap-ax (RBwsAP5Hac2ND). All work, if I leave them alone. FANTASTIC.

NOT FANTASTIC OR DESIRED: the RESET function to erase their config, since these were installed at various times by various people, who (and I am one of them) might have forgotten the password for access. See they work, reliably and we think, all is good. Then one year I want to upgrade their RouterOS/RouterBoot because I have a newer switch for small business, or for medium sized residence - and I find that I have forgotten where I kept the passwords for all those devices, or I never followed through in using a common password. (What's the use of a password to prevent access then, just give me a physical security key and I will then use it when upgrading).

So, yes, there are "simple" instructions (use paper clip to push reset button, and hold until either default config, or netboot) and you should either boot back into a known state (earlier rev) and then be able to log in --- BUT ---

What about the password that "might" have been set? Which method allows a clean factory fresh installation with no password? Like "Admin" and . See, today I had two wsAP from the same batch of 2020 hardware, and I found them and wanted to upgrade them. I also have TWO CRS-318 that are functional, but I wanted to upgrade them as well.

The RESET pin push trick didn't work as follows:

Option 1: Push reset button moments after inserting power.

Option 2: Push reset button before inserting power.

And on the wsAP and CRS-318 how small do you think that push button switch is? I understand (and I design) an SMT push button switch was used on the PCB, but why not make it larger and a PHYSICAL user-friendly RESET button?

Think about the open face of a CRS-318 in service, with the amount of wiring inserted - where do you think we have any space to insert a special tool (paper clip) keep it pressed while manipulating the power connection? Why not just have a RESET switch or a RESET button that can be easily accessed.

And if secrecy is such an issue - why not allow a tokenized backdoor so that it can wipe whole configuration on a one-key stroke action item if connected on a physical port, to a particular segmented port/socket combination and then the unit can be recycled? So connect to that, with the cryptographic token, and boom the configuration is wiped to factory default - and a blank password.

And if the company wants to make life easier for customers, why not allow lookup of the default password as set from the factory production line (in a customer portal) so that years later, the customers can input serial numbers and get the passkeys?

Hi there,
That’s quite a tricky issue—I’ve faced it too with models featuring dual power supplies. It’s a real hassle when you have racks packed with gear and need to reset a 328 unit. You’ve only got one pair of hands, yet the phone keeps ringing :slight_smile: Let me add a suggestion to back this up—or rather, propose a specific approach: the solution needs to be hardware-based, designed for two-handed operation, and front-facing—for instance, two buttons side-by-side. It really is a problem in critical situations.
Best regards and full support.

Don't they have racks with switches in the MikroTik server rooms? Maybe they should take a look and give some thought to these kinds of situations?

PS ->
BartoszP

Hi there—the question wasn't directed at me, but perhaps this was an issue unique to my setup: on several occasions, the VLAN settings tabs on my switches disappeared, member assignments vanished, traffic stopped flowing through the ports, and resets were required. Admittedly, these bugs didn't occur with version 2.18, but I have bitter memories of them happening with version 2.17 (specifically on the 326 and 328 switch models).

... there are no children in the server room, and child-proofing the outlets is irrelevant there anyway

There are no perfect devices :slight_smile:

When I bought a new washing machine - when kids were at 3..5 age - it took them circa 1min to bypass kid-protection to not open the front "door" of it.

RESET in front panel of device and of you, reachable with an pencil is asking for trouble. Some always will try to bypass password problem with reset as the first step.
How many times do you need to fully reset device in such an environment as yours?

I view this as just another case of the "mother may I" stupidity that rammed the gibberish easily lost initial passwords down our throats. In my world, there is zero place for either. If a user cannot comprehend why password changes are good, or what the reset button does, it's not the manufacturers job to make it more difficult for everyone else. Pain inspires learning . . . Use the reset wrong once or twice, and you learn not to. Make the process suck, and you are stuck with it forever . .

FWIW . . .

given I've built mikrotik networks as an early adopter, I've had to reset quite a lot when I have had units fail, get returned to depot and then repurposed and sent out again. I did mention that this current problem was for a smart residence (x14 wsAP, few years back + crs-328) and my own new residence compound (crs-328 x1 and crs-318x2, and 2 wsAP and 2 (so far) WAP ax -- that's how many passwords I have to keep track off.

What do you think I should do @BartoszP and others? Thanks for commenting. It's really funny that since 1996, there must be millions of RouterOS deployed, and the issue of primary/secondary/tertiary authentication for the admin account seems to have had NO IMPROVEMENT since the beginning of time. For example: "admin" with or without a default password. Sure, set up a mikrotik router on the internet and get DDOS attacks / hacks from minute 1.

So, they programmed a default password. Great. Then you try to reset the configuration to (say) CAP mode, guess what it does? you then get to change the password that was given during manufacturing. Great.

Few upgrade cycles later, something happens (or the box has issues) and you have to reset. What's the password then? the original one? the new one? another one?

n3rdx :
Sure, set up a mikrotik router on the internet and get DDOS attacks / hacks from minute 1.

I wouldn't agree with that :slight_smile: That is precisely when MikroTik is at its most secure—specifically regarding the WAN side. The LAN isn't designed to be attacked by its own owner, though that is something to keep in mind as well.

Regarding the issue of passwords on the new devices—I’m currently configuring a small batch of hEX units: about 60 devices, along with four 328 switches and four boxes of 260GS units. It’s frustrating, but it’s not without reason. I understand the situation, but we also need to see things from the manufacturer's perspective—they can't please everyone with every decision.
As for the reset button and the whole procedure—if we can manage the frustration, it’s really no big deal! Every paperclip counts!
Best regards.

Well,
netinstall solves everything and doesn't care about the password:

  1. Netinstall
  2. Set admin user and password
  3. Reload export
    Done.

That is, of course, assuming you don't care about backing up your exports to a safe location...
And then?
You could create a superuser, just for emergencies, where the password is the ether1 MAC address,
processed using a specific method you know how to replicate...
And you're all set.

Do you have any idea how many solutions I could come up with?
Dozens.

You need to know how to organize yourself and understand how the tools you use actually work.

Another example...
To reset a specific user's password, you simply need to create a script that,
if the reset button is pressed, for instance, using the sequence . . . _ _ _ . . . :rofl: [1]
resets the password to match the MAC address of ether1...


  1. Using hold time, for example 1s, pause, 1s, pause, 1s, pause, 10s, etc. and auto-reset the counter to 0 after 1 min when the button is not pressed... ↩︎

Well, initially, for every unit I prepared,
I would perform a "netinstall" regardless of the state it was in when it arrived at the office.

So, during the netinstall process, the password wasn't actually applied,
instead, it was stored on the device and automatically transmitted to my own internal database.
That way, I could just look up the serial number or MAC address and find the password right there.
It was just a matter of getting the job done...
Anyway, I stopped doing that later on.
It’s just a waste of time.
When you netinstall the device, or apply custom branding, it resets to the settings I defined,
using the initial startup password I chose myself.
So, why should I care about saving the passwords?
As long as the hardware isn't physically broken,
I can get back into it however and whenever I like,
without giving a damn about the factory password.

I thought that I had read in the netinstall docs that netinstall cannot change the default bs gibberish passwords.

Is my understanding incorrect? If so, I may have to netinstall everything I own out of the box . . . I really REALLY hate that bull$h1t!

(Or are you just changing it when you netinstall, such that a hard reset will still put back the gibberish?)

I like the idea of Netinstall, yet haven't yet been able to get one instance of netinstall to actually detect and start a router install session on my Windows 11 laptop, with a USB/ethernet dongle into a dumb ethernet switch, connected to a POE-Ethernet adapter that is powering/connecting to the wsAP or WAP ax device.

Why? Because I am trying to press (paperclip, screw driver) the .... RESET button contact. My frustration is (assuming the RESET button switch is not damaged somehow in the past from failed attempts) I am seeking the simplicity of the button press mechanism so I can reliably do it.

I'm pressing and hearing the "click" gently, and doing this both in option A and option B type (press then turn on) and (press after turn on) and waiting minutes - and nothing happens. This is with the laptop WiFi interface disabled.

If I had just one attempt at the various times I have tried it, then I would not have complained in my post.

So, what else could I do?

We're a bit out of sync with the time zone. There are various guides for netinstall; some involve setting up a virtual machine running Linux... Search the forum...

During the netinstall, using a custom script, you can set whatever password you like...
You can't set it for the default configuration.
At most, you can perform the netinstall without applying the defaults (which is what I do).
Then, you log in as admin without a password, paste a script that creates users and groups,
and select "reset-configuration", keeping the users you've already created while reloading the defaults (if you really want them),
or simply apply your own configuration script however you prefer.

Thanks. That's pretty much what I thought. It works, but makes recovery a far larger process than just reset button to defaults and reload config.

I guess short of reading and rewriting the prom, no way to get around the other . . .