A SecuryTik product · free

MikroTik labs in your browser,
Plug & Play.

SecuryTik Interactive Laboratory

SILAB is a network lab for MikroTik trainers and students, in the spirit of EVE-NG and PNETLab but focused on one job and made simple. Draw a topology, press start, and every router is a real RouterOS Cloud Hosted Router you reach with one double-click — a console in the browser, WinBox, WebFig or SSH.

On Ubuntu no VT-x is required: KVM when the host has it, software emulation when it does not. On Windows, WSL2 needs VT-x switched on.

Ubuntu 22.04 / 24.04 / 26.04 · Windows 10 / 11 via WSL2 · RouterOS 7.15+
Install

One line. One server. Labs in minutes.

The installer checks the release's signature and the bundle's SHA256 before anything runs, asks you to accept MikroTik's licence, and downloads RouterOS from MikroTik. Then open the server in a browser and sign in as admin / admin.

Linux

Ubuntu 22.04 / 24.04 / 26.04, amd64 or arm64 — as root. No VT-x needed.

install.sh — bash
curl -fsSL https://silab.securytik.com/install.sh | sudo bash

Windows

Windows 10 (2004+) or 11 — in PowerShell, not Command Prompt (cmd). When Windows asks for administrator permission, click Yes. Runs in its own WSL2 instance.

install.ps1 — PowerShell
irm https://silab.securytik.com/install.ps1 | iex
Measured on a host with no KVM

Real routers, even under software emulation.

SILAB is tested where emulators struggle most: real RouterOS 7.24.4 on a host with no hardware virtualization at all. With KVM it only gets faster.

34 s
Clean 2-router lab, up and provisioned
39 s
Router added to a running lab, linked
~220 MB
RAM per idle router
4–6 %
Of one core per idle router
What you get

Everything a MikroTik bench has. Nothing to wire.

Every piece below ships in the same installer — no plugins, no appliance images to hunt for, no licence server.

Real routers, real labs

Every router is a genuine MikroTik CHR — the RouterOS your students meet in the field. Router, Switch, Hub, PC and Internet nodes, cabled ether1..N exactly as drawn. Add routers and cables while the lab runs.

No VT-x required on Linux

On Ubuntu: KVM when the host has it, QEMU software emulation (TCG) when it does not — a cheap VPS, a laptop VM, a nested cloud instance, and a router still boots in about half a minute. On Windows, SILAB runs in WSL2, which needs VT-x / AMD-V switched on in the BIOS.

One double-click away

A console in the browser that works even when the student has erased every IP. WinBox, WebFig and SSH through fixed host ports — right-click → WinBox opens already logged in.

Cut a cable, break a link

Unplug and plug a cable, or impair it on purpose: delay, jitter, loss, bandwidth. Point-to-point cables pass every frame — STP, LACP, LLDP, MNDP and VLAN tags.

Wireshark, live

Right-click a cable → Capture in Wireshark: that link's traffic, live, both directions. The capture runs on the SILAB server, so Wireshark needs no capture rights on your PC.

Virtual PCs

DHCP client, static address or PPPoE client with a service name. Each PC has a console with ping, trace, nslookup, web, arp and route — and no host shell behind it.

Bulk actions

One change on every router at once: clock sync, NTP, time zone, DNS, RouterOS commands, RouterOS upgrade, reboot, hard reset, power cycle — with a result per router.

Power, like the real bench

A VMware-style power menu: power on, shut down, reboot, reset, power off (pull the plug), power cycle and wipe the disk. Power-cycle confirms RouterOS device-mode changes.

Tiny, shareable labs

A .silab file is the diagram plus one .rsc per router — usually a few KB. The receiver's SILAB rebuilds the lab from its own RouterOS image; imports are validated strictly.

Light on resources

One base image per RouterOS version and a thin copy-on-write overlay per router; identical memory pages shared; per-router CPU and RAM caps. Hubs, PCs and Internet clouds cost almost nothing.

Signed updates & backups

Updates are signed and show What's new first; if one fails, the previous version is put back automatically. Backup & restore covers labs, accounts and settings, with a daily automatic copy.

Free to use

No licence server, no sign-up. RouterOS images are downloaded from MikroTik at install and checksum-verified — never redistributed.

How it works

Install, draw, start, double-click.

No appliance images, no bridges to configure by hand, no port maps to remember. SILAB owns the plumbing — you build the network.

Draw the lab

A topology on a canvas. Real routers behind it.

Add nodes with + Node, cable them port to port with + Connect, and press Start lab. The canvas shows the addresses exactly as RouterOS lists them, and keeps working while you add more.

  • Routers and switches are MikroTik CHR; hubs, PCs and Internet clouds need no VM
  • Rename a router on the canvas and its RouterOS identity follows, live
  • Management kept in its own VRF — out of the student's routing table and out of OSPF / BGP
  • Ping between any two devices — five echoes, result in a pop-up
OSPF basics Running
ether1 · 10.0.12.1/30 ether1 ether2 R1 R2 Internet LAN hub PC1
+ Node + Connect Ping Stop lab
Reach every router

The part EVE-NG makes hard, made one click.

Double-click a router for its console in the browser — it works even with no IP address configured. Right-click for WinBox, WebFig, SSH and power. Every router also gets fixed ports on the SILAB host, from the LAN or the Internet.

  • WinBox opens already connected — address, user and password filled in
  • R1 is always :20010 for WinBox, :20011 for SSH, :20012 for WebFig
  • Ports named ether1..N inside RouterOS, matching the diagram
Console — R1
MikroTik 7.24.4 (stable)
R1 Login: admin
[admin@R1] > /ip address print
 #   ADDRESS         INTERFACE
 0   10.0.12.1/30    ether1
Break it on purpose

Cables and power that behave like hardware.

Pull a cable and the router sees no link. Add 50 ms of delay and 2% packet loss and watch OSPF cope. Pull the plug and RouterOS loses exactly what a real power cut would. Then capture the cable in Wireshark to see why.

  • Unplug / plug, delay, jitter, loss and bandwidth per cable
  • Per-router CPU and RAM caps — one flooded router cannot freeze the host
  • Wipe a router's disk to start it over from the base image
Cable R1:ether1 ⇄ R2:ether1
State plugged
Delay 50 ms
Loss 2 %
Bandwidth 10 Mbit/s
Capture in Wireshark Unplug Power off (pull the plug)
Backed by SecuryTik

Built by people who deploy MikroTik for a living

SILAB comes from SecuryTik, the team behind SAMM for MikroTik ISPs and SILA for certification practice. Practise the exam on SILA, then build the network on SILAB.

Frequently asked questions

What people ask before installing SILAB.

What is SILAB?

SILAB (SecuryTik Interactive Laboratory) is a network simulation lab for MikroTik trainers and students, in the spirit of EVE-NG and PNETLab but focused on MikroTik. Every router is a real RouterOS Cloud Hosted Router (CHR) running on QEMU, reachable from the browser console, WinBox, WebFig or SSH.

Do I need VT-x or KVM?

Not on Linux. SILAB uses KVM when the host has it and falls back to QEMU software emulation (TCG) when it does not, so a cheap VPS or a VM without nested virtualization works. On Windows, SILAB runs inside WSL2, and WSL2 itself needs hardware virtualization (Intel VT-x / AMD-V) switched on.

What does SILAB need to run?

Ubuntu 22.04, 24.04 or 26.04 (amd64 or arm64) with root access, or Windows 10 (version 2004 or newer) / 11. Two cores and 4 GB of RAM run a handful of routers; plan about 200–300 MB of RAM per router.

Is SILAB free?

Yes. SILAB is free to use, with no licence server and no sign-up. RouterOS CHR images are downloaded from MikroTik under MikroTik's own licence, which the installer asks you to accept.

Can SILAB share a server with SAMM or other software?

Yes. SILAB is independent: it adds its own nginx site, bridges and firewall table and never touches your LAN interface or other sites. When port 80 is already taken, for example by SAMM, the web UI moves to port 8088.

Your first MikroTik lab is one command away.

Install on any Ubuntu server or Windows PC, open it in a browser, draw two routers and a cable, and press Start lab.