Services
Deep in one vendor, rather than shallow in ten.
Every engagement below is MikroTik work. If your problem turns out not to be a MikroTik problem, we will tell you that too — quickly, and without a bill for discovering it.
Support
Remote and onsite support
The core of what we do. You get an engineer who has seen your network before, not a first-line script reading from a knowledge base.
- Fault diagnosis and resolution, remote first
- Configuration changes, reviewed before they are applied
- RouterOS upgrades planned around your working hours
- Onsite attendance nationwide when remote will not do it
- Emergency recovery for locked-out or bricked devices
What we need from you
Remote support works properly when access is set up once, correctly:
- A read-only monitoring user, restricted to our IP address
- A WireGuard or IPsec tunnel for hands-on work
- Written authority for who may approve changes
We will never ask you to open a management port to the public internet. If yours is already open, that goes to the top of the audit list.
Typical deployments
- Hotels, lodges, guesthouses and backpackers
- Schools and student residences
- Caravan parks, campsites and resorts
- Conferences, festivals and temporary events
- Retail and hospitality guest WiFi
- Buses, trains and other moving vehicles
Public WiFi
Hotspot and captive portal
RouterOS has one of the most capable hotspot engines available at any price. Getting it to behave — vouchers that expire correctly, guests who cannot see each other, bandwidth that is shared fairly at full occupancy — is the part that takes experience.
- Branded captive portal and terms acceptance
- Voucher, room-number or paid-access models
- RADIUS integration and user accounting
- Per-user bandwidth limits and fair-use queues
- Guest isolation and segregation from your business network
Wireless
Point-to-point and point-to-multipoint links
Connecting buildings without a trench. We survey the path first, because a link that is marginal in winter is a support call in summer when the trees are full.
- Path survey, line-of-sight and Fresnel assessment
- Link budget and capacity planning before you buy hardware
- Installation, alignment and weatherproofing
- Mast, tower and rooftop deployments
- Redundant paths and automatic failover
- Documented handover with actual signal figures
Where this earns its keep
Farms and agricultural operations. Factories and warehouses with separate offices. Game reserves and lodges. Schools with multiple campuses. Any site where fibre is quoted in months and hundreds of thousands of rand.
A well-planned wireless link is usually installed within a week and, once it is up, is boring — which is the highest praise a link can get.
The most common findings
What we see over and over on networks we take on:
- Winbox or the web interface reachable from the internet
- Default or shared admin credentials still in use
- RouterOS versions years behind, with published exploits
- No firewall rules on the input chain at all
- No configuration backup anywhere
- Nobody able to say what the network actually looks like
Security
Hardening and compliance support
MikroTik ships permissive by design, so that the device works before you have configured it. That is convenient on the bench and dangerous in production.
- Full configuration audit against a written baseline
- Management access locked to tunnels and named source addresses
- Firewall rebuild on input, forward and output chains
- Per-engineer accounts with least privilege, no shared logins
- RouterOS and RouterBOOT upgrade planning
- Network segmentation for guest, staff, payment and OT traffic
- Logging and retention to support POPIA obligations
We are network engineers, not your compliance officer — we secure the infrastructure and give you the evidence your auditor asks for.
Carrier & ISP
ISP and WISP engineering
If you sell connectivity, your MikroTik estate is your product. We work on it the way an operator does, because we run a subscriber network ourselves.
- PPPoE and hotspot subscriber management at scale
- Queue trees, PCQ and fair bandwidth distribution
- BGP peering, OSPF design and route filtering
- CGNAT, IPv6 deployment and address planning
- MPLS and VPLS between sites
- High availability with VRRP and redundant upstreams
- Capacity planning from your own traffic data
Overflow engineering
Several of the operators we work with have their own technical staff. We are the people they call for the jobs that come up twice a year — a core upgrade, a new peering session, a migration that has to happen in one maintenance window.
Retainer or per-project, whichever suits how you budget.
Not sure which of those you need?
Most clients start with an audit. You get a documented picture of your network and a prioritised list of what to fix — useful whether or not you carry on with us.