Hardening Mikrotik

Hi I try to hardening my mikrotik but hope there are some guilde lines.
I found some firewall rules on internet.
I found some documentation about disabling ip services.

What I don’t found is how to configure https for webfig and don’t use http for it.
Can someone help?

In /ip service you can see the www-ssl service. But you would need a certificate to establish a connection I guess, otherwise there could not be encrypted connection without it.

Ok and ho to create a certificate in mikrotik?

http://wiki.mikrotik.com/wiki/Manual:Create_Certificates

I read that site but I cant sign my certificate.
I have a template created.
Now need to sign it and want to do it command line.
Name is test-cert
How to sign this?

The best method for hardening is to use Metal routerboard and aplly to it “Martensitic transformation” :unamused: :laughing: :laughing: