How Reliable Are MikroTik Routers for Small Business Networks?

Hi everyone,

I'm currently planning a network upgrade for a small business and MikroTik is one of the platforms I'm seriously considering.

For those who have deployed MikroTik in production, how has your experience been with long-term stability, RouterOS updates, VPN performance, and overall reliability?

I'm especially interested in environments with around 30–100 users where uptime and easy management are important.

I'd appreciate hearing about real-world deployments, any challenges you've faced, and which MikroTik models you would recommend for this type of setup.

Thanks in advance!

It all boils down to the skill of the one configuring the network.
Has networking skills = the best ever equipment that money can buy in this lifetime.
Lacks networking skills = go buy some TP-Link/Asus/Ubiquiti etc.
Ez.

Thanks for sharing your perspective. I agree that the person configuring the network has a huge impact on its overall performance. Even high-end hardware won't deliver good results if the design or configuration isn't done properly.

That said, I also think the choice of hardware depends on the deployment. Different vendors have their own strengths when it comes to management, scalability, and long-term maintenance.

I'm currently comparing MikroTik with Ubiquiti for a few upcoming projects, so it's really helpful to hear opinions from people who have worked with both in production. Have you had the chance to deploy both, or have you mostly worked with MikroTik?

Buy both brands and try to setup eg. home lab and check yourself what are the pros and cons.

Selfexperience is the best judge.

What I am missing are base requirements...
A bit hard to provide recommendations/experiences if nobody knows what it is going to be used for and in which context ?

I'm managing IT for a SMB, and in the company network there are as of now 26 Mikrotik Switches - from the small RB260GS to the 48 port CRS354 and also L3 switches like CCR1009 and CCR2004.

On customer sites we also run several CCR1072 and RB40xx with encrypted traffic between them.

My reasons are:

  • Trust. Mikrotik is European, and this is important since the company serves many govermental organisations. You may research how often Cisco has been cought with backdoors, forgotten passwords etc.
  • Comprehensive Featureset
  • Pricing

Problems: not many over the 9 years I work here. These boxes usually just work.

I have both Ubiquiti and MikroTik routers at the customer edge. They each have pros and cons.

MikroTik is like a Swiss army knife, and you can pretty much make it do anything you want, at a good price. But it does require a bit of learning how to manage the equipment and troubleshoot things.

Ubiquiti gives you a prettier pane of glass and an easier way to give the customer a management view of all the same things, at the cost of dialing down some more exotic functionality. VPNs are a little harder to set up in some cases, routing protocols are limited, and the firewall setup is confusing (for me). But the reporting and stats are well worth, especially for customers where I don't need a whole lot. And their WiFi works better for my needs.

As suggested, get a couple of each and lab them up and see how you like it.

They work great, hardware issues are not frequent and when they occur they usually are in the plug-pack power supply. Easy to replace it, or select a model with built-in (redundant) powersupplies.

An issue I have had is that most IT management companies do not know it and do not want to support it. They have their employees trained in stuff like Cisco, Juniper, etc and that is what they want to support.

Not an issue when you manage it yourself, and also this could be different depending on the type of IT companies you have locally (the suit-and-tie or more of a nerds type).

My personal opinion:

I've used Extreme Networks, Ruckus, MikroTik, HPE Aruba, Lancom, SonicWall and Ubiquity in a professional and private context.

My favorites are:

Mikrotik for routing and switches. Hardware is well-made and very robust, especially for this price-performance ratio. Even harsh environment condidtions are capable, like hot/warm rooms etc.. There are no wizards, helpers or whatever, except the quick configuration option. You have to know what you are doing. Personally I find it very pleasant that Mikrotik isn't doing some snakeoil cybersecurity stuff - especially if this "security enhancing" stuff tends to phone home or requires expensive subscriptions. However, the user interface is very straight forward, I am more like the visual guy than the CLI guy when it comes to networks. My oldest switch is over 10 years old and still gets RouterOS Updates up to Version 7.

Mikrotik for WLAN if you only need one or two APs and don't have high demands for WIFI. As much as I love Mikrotik for their routers and switches, WLAN is not their strength IMHO.

Ubiquity for WLAN APs, when you are on a budget. Easy to configure, reliable, very good price-performance ratio.

Ruckus for WLAN APs, when you have enough budget and/or need exceptional WIFI-Performance. Easy to configure and not that expensive, if you compare to other competitors.

Again, this is my personal opinion, all brands I have used have strengths and weaknesses. The ones above are my personal favorites. About personal taste, you can't discuss. :wink:

In a lot of professional environments there will be a challenge to use MikroTik. There are too many so called professionals, who don't know/want MikroTik and are talking poorly about it, without any plausible evidence. If there is the slightest network issue, by default the MikroTik stuff is the reason, because its not one of the big old networking company stuff, and because that, it must be automatically bad. You have been warned and should be able to handle these kinds of professionals.

Mikrotik for routers is a no-brainer. Cheap, reliable, ROS updates free for all devices basically forever (maybe yours runs out of RAM or storage eventually)... but you need to know what you're doing, it's a lot more like Linux networking than Cisco so if you know that you'll be comfortable.

Worth reading. Very similar topic.

Thanks for this link. It confirms what I am already thinking. It's just covering your a*s. Blame someone or something else for why a security breach or failure occurred. MikroTik makes this hard.

I've seen this too many times: Businesses spending huge amounts of money on cybersecurity but getting hacked at least once a year.

I'm in the "if you pay someone to secure your shit, be prepared because now at least one extra person knows how secure is your shit" boat.

Small business 200 people or less cannot afford the costs associated with effective IDS and content management ... they can only afford common sense disciplines and solid tech support but that will change with AI in a few years.

MikroTik routers for small business are excellent starting with CCR line of gear ... For Wireless I would suggest bypassing MikroTik and recommend Ubiquiti Access Points including the 2nd generation of Controllers like the ubiquiti uck-g2-ssd ...

ONLY as a side-side note, I have often seen in case of intrusions how the blame has been given to this (or that) supposed vulnerability only because it exists or to a (minor) mis-configuration (without actual proof that it was actually used to get in).

While the actual credentials were on public display on a post-it on a monitor or some were given to some external personnel and never revoked.

I agree with this. In my use case, the MikroTik WLAN still lags behind some of the competition.

Small business 200 people or less cannot afford the costs associated with effective IDS and content management ... they can only afford common sense disciplines and solid tech support but that will change with AI in a few years.

I know businesses of this size are investing six-digit sums in cybersecurity with very poor results. Because they have to by law. The biggest issue is that security by design isn't a thing, but making horrendously insecure stuff with some magic snakeoil secure.

By the way, I've never seen an IDS and some of the other magic stuff preventing a successful attack.

Especially industry- and sector-specific software is often really terrible in multiple ways when it comes to security and data integrity.

While the actual credentials were on public display on a post-it on a monitor or some were given to some external personnel and never revoked.

Absolutely. No IDS and other snakeoil will prevent such negligence and in my experience this is the main intrusion method.

I evaluated MikroTik and Ubiquiti for a similar, but smaller project a couple of months ago. We were using Sophos and Lancom equipment in the past and the old Lancom management software was Windows x86 only and usability was horrible in comparison to the current WinBox implementation. Their newer hardware required crazy yearly licensing fees.

I really like the Unifi Access Points a lot because they combine a good management interface with an affordable choice in hardware and very reliable wireless networking. Reliable wireless configuration ican be a complicated matter which Unifi simplifies a lot. We're running our own controller in our network (over VPN) with good results. Their hardware controller solution is a bit flimsy, though.

Unifi also can be an appealing platform for managing a multi-client setup through their centralized cloud platform. Routing used to be limited but the last update seems to have improved that. Anything you do with Unifi is either doing it exactly the way they indented it to be done or you're fighting windmills. That is why we decided against their firewall solutions.

What I absolutely dislike about Unifi is that they do everything that they can to lock you into their cage. Topology for non-unifi devices? Not possible, even though LLDP is installed on the devices. LAG: they don't even mention how it needs to be set up on third party devices but it works out of the box between Unifi devices. SFP modules work between their products but you need to figure out which settings need to be configured on other manufacturers devices (there are basically no options on the Unifi side).

If you read through the MikroTik IPSEC documentation and you do not understand what they are talking about, you should really ask yourself if that is going to be the right technology for you. You can do great things for a really affordable price without subscription or license fees. However, you really need to understand what you're doing. Even though there are many complaints here about the new Winbox, I never had any real problems with it and was able to get started with a complex setup in a very short amount of time.

I found diagnostics to be very helpful (tool sniffer quick) and all the other diagnostic tools. The only exception is DNS diagnostics, which I find to be poorly implemented.

I haven't really figured out how they decide which features go into which products for what reason but there is plenty to choose from. It is beyond me, why there is absolutely no IPSEC VTI support. If you need that, e.g. for compatibility reasons with other endpoints, you're completely out of luck. The communication around that PPP security problem has left a hugely negative impression.

I would go for Unifi again for Wireless. Switching can go either way, depending on your exact needs. Unifi firewalls might be a good fit for a service provider setup that manages many non-related client networks. Mikrotik is a good and performant routing and firewall platform.

Hope that helps.