Getting started
Overview & architecture
SILAB — SecuryTik Interactive LABoratory —
is a network simulation lab built for MikroTik trainers and students. Draw a topology, press start,
and every router is a real RouterOS Cloud Hosted Router (CHR) you can reach with one
double-click: a console in the browser, WinBox, WebFig or SSH.
Who SILAB is for
Trainers preparing a class, students practising for a MikroTik certification, and
engineers who want to try a change on real RouterOS before touching production. SILAB is in the
spirit of EVE-NG and PNETLab, but focused on one job and made simple.
How it works
SILAB runs on plain QEMU. When the host has KVM, SILAB uses it; when it does not — a
cheap VPS, a laptop VM, a nested cloud instance — it falls back to software emulation (TCG) and
still boots a router in about half a minute. Routers share one base image on disk and identical
memory pages in RAM, and switches, PCs and Internet clouds cost almost nothing.
Browser→
nginx→
silab-web→
silab-engine→
QEMU + CHR per router
| Part | Role |
silab-web | The web UI, as the unprivileged silab user, on 127.0.0.1 only behind nginx |
silab-engine | Root service: routers, cables, the management network and port forwards; talks to the web over a unix socket |
| One QEMU per router | Each router runs in its own systemd unit with CPU and RAM caps, so one flooded router cannot freeze the host |
| Links | tc links between ports pass STP, LACP and LLDP; hubs, PCs and Internet NAT clouds are Linux bridges and namespaces, not VMs |
| Management network | Isolated, DHCP only, kept inside each router in its own VRF (vrf-mgmt) |
What SILAB does
Real routers
Genuine MikroTik CHR routers and switches, cabled ether1..N exactly as drawn.
One click away
Browser console, WinBox, WebFig and SSH for every router.
Cables & power
Unplug, impair, capture; power off, reset, power cycle, wipe.
Virtual PCs
DHCP, static or PPPoE clients with ping, trace and more.
Trainer tools
Bulk actions on every router, live rename, tiny shareable labs.
Like every SecuryTik product
Signed updates, backup & restore, day and night themes.
Start with Installation,
or use the menu to jump to any topic.
Getting started
Installation
SILAB installs everything it needs — QEMU, the RouterOS image, nginx and its own
services — from one command. It is independent: it installs on a clean Ubuntu box and
sits beside anything else already on the host without touching it.
Every install is verified: the bootstrap checks the release manifest's
signature against SILAB's release key and the bundle's SHA256 before
anything runs, then asks you to accept MikroTik's licence.
Pick your platform:
Installation
Linux (one command)
On Ubuntu 22.04, 24.04 or 26.04 (amd64 or arm64), run as root:
curl -fsSL https://silab.securytik.com/install.sh | sudo bash
The installer downloads from our download bucket, and from SILAB's GitHub release by
itself when the bucket cannot be reached — there is nothing to choose.
What happens
- The bootstrap fetches the latest release manifest, checks its signature and expiry,
downloads the bundle and checks its SHA256. A mismatch stops the install before anything runs.
- It asks you to accept MikroTik's licence for RouterOS CHR, then downloads the latest
stable CHR image from MikroTik and verifies its SHA256. The image is never redistributed by SILAB.
- It installs QEMU, nginx and SILAB's services, and publishes the web UI on
port 80 — or 8088 when port 80 is already taken, for example by SAMM.
First sign-in
Open the server in a browser and sign in:
Login URLhttp://<server>/
·
Usernameadmin
·
Passwordadmin
Change the password right away under System → Profile.
SILAB shows a warning while the default password is in use.
Unattended installs
Without a terminal (cron, CI, ssh -T) the installer runs unattended. Set
SILAB_ACCEPT_MIKROTIK_LICENSE=1 to accept MikroTik's licence without the prompt — see
Requirements & options.
Installation
Windows (WSL2)
SILAB runs on Windows 10 (version 2004 or newer) and Windows 11 in its own WSL2 instance,
set up by one installer. Open PowerShell — not Command Prompt (cmd) — and run the
line below. If PowerShell is not running as administrator, Windows asks for permission: click
Yes and the installation continues in a new administrator window.
irm https://silab.securytik.com/install.ps1 | iex
It downloads from our download bucket, and from SILAB's GitHub release by itself when
the bucket cannot be reached.
The bootstrap downloads the full installer to
%ProgramData%\SILAB\silab-windows.ps1 and runs it from there, so it can elevate itself and
carry on after a restart.
What happens
- It enables WSL2. The first time this needs one restart of Windows; setup then continues by
itself.
- It imports a dedicated Ubuntu 24.04 instance named SILAB
(checksum-verified). Your other WSL distributions are untouched.
- It installs SILAB inside that instance with the Linux installer.
- It adds a SILAB icon to the desktop and the Start menu: a small menu to
Start, Stop, see the Status, Open it in
the browser, and Share on the LAN so other PCs — and their WinBox — can reach the lab.
Hardware virtualization is required on Windows
Unlike Linux, WSL2 cannot run without Intel VT-x / AMD-V. On a real PC, switch
on "Intel Virtualization Technology" or "SVM Mode" in the BIOS/UEFI setup. Inside a virtual machine it
must be passed through to the guest — in VMware tick "Virtualize Intel VT-x/EPT or AMD-V/RVI" with the
VM powered off. The installer checks this and says what to change.
Installing from a downloaded file
The full installer can also be run directly, for example from a copy on a USB stick:
powershell -ExecutionPolicy Bypass -File silab-windows.ps1
Uninstalling
-Uninstall removes the SILAB instance, the shortcut and the LAN sharing rules:
powershell -ExecutionPolicy Bypass -File "$env:ProgramData\SILAB\silab-windows.ps1" -Uninstall
Installation
Requirements & options
Requirements
- Linux: Ubuntu 22.04, 24.04 or 26.04, amd64 or arm64, with root / sudo
access. KVM is used automatically when
/dev/kvm is usable; without it SILAB runs under
software emulation — no VT-x needed.
- Windows: Windows 10 version 2004 (build 19041) or newer, or Windows 11,
with hardware virtualization (VT-x / AMD-V) switched on for WSL2.
- Size: 2 cores and 4 GB of RAM run a handful of routers; plan about
200–300 MB of RAM per router.
- RouterOS: CHR 7.15 or newer, downloaded from MikroTik.
What the installer sets up
| Component | Details |
| QEMU | qemu-system-x86 (or -arm on arm64 hosts) and qemu-utils; KVM used automatically when /dev/kvm is usable |
| RouterOS CHR | Latest stable image downloaded from MikroTik after you accept MikroTik's licence; SHA256-verified |
| nginx | Publishes the web UI on port 80 (or 8088 when 80 is taken, e.g. by SAMM) as SILAB's own site, added without touching other sites |
silab-web | The web UI as the unprivileged silab user, on 127.0.0.1 only (behind nginx) |
silab-engine | Root service: routers, cables, management network, port forwards |
| Timers | Daily release check (silab-updater.timer), daily backup at 04:00 (silab-backup.timer), memory merging (silab-ksm) |
| Networking | Its own bridges (sl*) and nftables table (inet silab); never touches your LAN interface |
| Host firewall | Where Docker or ufw drop forwarded traffic, silab-fw.service adds narrow ACCEPT rules (tagged silab) for the lab's port forwards, Internet clouds and hubs, and re-adds them at every boot |
Docker or ufw added later?
If you install Docker or enable ufw after SILAB, run systemctl restart silab-fw
(or reboot) so the lab's rules are added again.
Environment overrides
Set these in front of the install command, e.g.
curl -fsSL https://silab.securytik.com/install.sh | sudo SILAB_HTTP_PORT=8080 bash.
| Variable | Effect |
SILAB_HTTP_PORT=N | Web UI port (default 80 when free, else 8088) |
SILAB_APP_PORT=N | The app's own port on 127.0.0.1, behind nginx (default 8089) |
SILAB_ACCEPT_MIKROTIK_LICENSE=1 | Accept MikroTik's licence without the prompt |
SILAB_SKIP_IMAGE=1 | Offline host: install without downloading RouterOS (silab image add <file> later) |
SILAB_VERBOSE=1 | Raw command output instead of the progress display |
Getting started
Your first lab
Two routers and a cable, from an empty canvas to a ping across the link.
- Sign in as
admin / admin and change the password under
System → Profile.
- Create a lab, then open Lab → Topology.
- Click + Node and add two Router (CHR) nodes — R1 and R2 in
this example.
- Click + Connect, click R1 then R2, and pick the ports — for example
ether1 on both.
- Press Start lab. Under software emulation a clean two-router lab is up and
provisioned in about half a minute.
- Double-click R1 to open its console, give
ether1 an address on each router, and
use Ping — click R1, then R2 — to test the cable.
One lab at a time
SILAB runs one lab at a time. The labs manager creates, opens, duplicates, renames, exports and
imports .silab files.
The lab file
A lab is a small YAML diagram. Exported as a .silab file it carries the diagram
plus one .rsc per router — usually a few KB. The receiver's SILAB rebuilds the lab from its own
RouterOS image, and imported files are validated strictly: no host paths, no raw QEMU arguments.
silab: 1
name: OSPF basics
routeros: "7.24.4"
nodes:
- {id: 1, name: R1, kind: router, x: 100, y: 100, config: R1.rsc}
- {id: 2, name: R2, kind: router, x: 400, y: 100}
- {id: 3, name: LAN, kind: hub, x: 250, y: 300}
- {id: 4, name: PC1, kind: pc, x: 250, y: 450}
links:
- {a: {node: 1, port: 1}, b: {node: 2, port: 1}, delay_ms: 20}
- {a: {node: 2, port: 2}, b: {node: 3}}
- {a: {node: 4}, b: {node: 3}}
A lab pins its RouterOS version, so a shared lab behaves the same everywhere.
Building labs
Nodes & cables
Add nodes with + Node and cable them port to port with
+ Connect — while the lab runs, with no restart.
Node types
| Node | What it is |
| Router (CHR) | A genuine MikroTik Cloud Hosted Router. Ports are named ether1..N inside RouterOS, matching the diagram. |
| Switch (CHR) | A CHR set up as a switch. |
| Hub | A shared segment — a Linux bridge, no VM. |
| PC | A virtual PC: DHCP, static or PPPoE client with its own console. See Virtual PCs. |
| Internet (NAT) | A NAT cloud that gives the lab a way out to the Internet, never onto the host's LAN. |
Rename a router on the canvas and its RouterOS identity follows, live. Each router can carry a
startup configuration (.rsc), applied on first boot.
Cables
- Point-to-point cables pass every frame: STP, LACP, LLDP, MNDP and VLAN tags.
- Unplug and plug a cable, or impair it on purpose: delay,
jitter, loss, bandwidth.
- Several cables between the same two nodes are drawn side by side, each with its own labels.
- Right-click a cable to capture it live in Wireshark.
Power
Right-click a router for a VMware-style power menu:
| Action | What the router sees |
| Power on | Power applied |
| Shut down / Reboot | A clean shutdown or reboot |
| Reset | The reset button — no shutdown |
| Power off (pull the plug) | Power loss: RouterOS loses exactly what a real power cut would |
| Power cycle | Unplug and replug — also how RouterOS device-mode changes (container, traffic-gen…) are confirmed |
| Wipe | The disk goes back to the base image |
CHR free licence
An unlicensed CHR is limited to 1 Mbps upload per interface. That is fine for configuration
labs; keep it in mind for throughput tests.
Building labs
Reaching a router
Double-click a router for its console in the browser. It works over the router's serial
port, so it keeps working even when the student has erased every IP address. Every router also gets
fixed ports on the SILAB host, reachable from the LAN or the Internet.
| Way | Where |
| Console | Double-click the router → Console (browser) |
| WinBox | <host>:20000 + id×10 — R1 is :20010 |
| SSH | ssh -p <20000 + id×10 + 1> admin@<host> |
| WebFig | http://<host>:<20000 + id×10 + 2> |
So router 1 answers WinBox on 20010, SSH on 20011 and WebFig on 20012; router 2 on 20020, 20021
and 20022. Routers log in as admin / admin.
ssh -p 20011 admin@<silab-host>
WinBox in one click
Right-click a router → WinBox and WinBox opens already connected, with the
address, user and password filled in. A web page cannot start a program on your PC by itself, so this needs
the WinBox helper, installed once per PC from System → Helpers:
- Windows — download the helper, right-click it → Run with PowerShell. If
it cannot find WinBox, it asks where
WinBox.exe is. Restart the browser once.
- Linux — download the helper and run
sh silab-winbox-linux.sh (not as
root). It finds WinBox, or asks for the path of the WinBox binary.
- macOS — until a helper exists, right-click a router → Links → WinBox copies the
address.
The helper needs no administrator rights. You need WinBox itself first, from
mikrotik.com/download.
The management port
SILAB reaches each router through a management port kept in its own VRF,
vrf-mgmt: out of the student's routing table and out of OSPF and BGP. The student's ports stay
ether1..N, exactly as drawn.
Building labs
Virtual PCs
A PC node is a lightweight client with no VM behind it. Set its IP from the canvas —
DHCP client, Static, PPPoE client (optionally only the
server offering a given service name) or No address — or from its console. The console
has no host shell behind it; these are its commands:
| Command | What it does |
ip | Show address, gateway, DNS and mode |
ip dhcp | Get an address by DHCP (renews while the lab runs) |
ip 192.168.88.10/24 192.168.88.1 1.1.1.1 | Static address, gateway and DNS (a dotted mask works too) |
ip none | No address |
pppoe USER PASSWORD [SERVICE] | Dial PPPoE (redials by itself); pppoe alone shows the state |
ping HOST [-c COUNT | -t] | Ping; -t runs until Ctrl-C |
trace HOST | The path, hop by hop (also tracert, traceroute) |
nslookup NAME [SERVER] | Ask DNS |
web URL | Fetch a page as text, e.g. web http://192.168.88.1 |
arp · route · clear · help | Neighbour table, routes, clear the screen, the command list |
Ping between any two devices
Next to + Connect on the topology, Ping tests reachability
without opening a console: click two devices, five pings run in the background, and the result opens in a
pop-up. SILAB pings the address on the subnet the two share, else the target's first address; an Internet
node as the target pings 8.8.8.8.
Building labs
Capture in Wireshark
Right-click a cable → Capture in Wireshark: Wireshark opens on your PC and shows
that cable's traffic live, in both directions, until you close it.
Install the Wireshark helper once
Like WinBox, this needs a small helper per PC, from System → Helpers.
It needs no administrator rights.
- Windows — download the helper, right-click it → Run with PowerShell. If it
cannot find Wireshark, it asks where
Wireshark.exe is. Restart the browser once: capture links
then open Wireshark without asking.
- Linux — download the helper and run
sh silab-wireshark-linux.sh (not as
root). It finds Wireshark, or asks for the path of the wireshark binary. It needs curl.
You need Wireshark itself first, from
wireshark.org.
Good to know
The capture runs on the SILAB server, so Wireshark needs no capture rights on your PC. Up to 4
captures run at once, and a capture link works once, within a minute.
Building labs
Bulk actions
Lab → Bulk actions makes one change on every router of the lab —
or the ones you tick — and shows the result per router.
| Action | What it does |
| Clock sync | Every router's clock and time zone from the SILAB host, so logs line up across the lab |
| NTP | Turn on the NTP client with up to 4 servers |
| Time zone | Set a zone name such as Asia/Beirut or UTC |
| DNS | Set the DNS servers |
| RouterOS commands | Run a script on every router |
| RouterOS upgrade | RouterOS's own updater, on a chosen channel — the routers need a path to the Internet (an Internet node) |
| Reboot / hard reset / power cycle | Power every router at once |
| Reset the lab | Back to its start |
System
Updates
System → Updates shows the installed version, the latest release
and What's new. A daily timer checks for new releases.
- Apply update downloads the signed release and checks it.
- It backs up the install to
/var/backups/silab, swaps in the new files and restarts
the engine and the web. Running routers keep running.
- If anything fails, the previous version is put back automatically.
After an Ubuntu release upgrade (22.04 → 24.04 → 26.04) the services rebuild SILAB's Python
environment themselves on their next start; re-running the installer also works.
RouterOS versions
Several RouterOS versions can be installed side by side, and SILAB tells you when a newer
RouterOS is out. Nothing updates on its own: a lab pins its version. Add one from the command line:
silab image latest
silab image pull 7.24.4
silab image list
System
Backup & restore
System → Backup & restore creates, downloads, uploads and
restores backups.
- Every backup holds every lab with its startup configs, the accounts and the settings.
- Tick Include the routers' disks to keep their full state too — the file is larger.
- RouterOS images are not included; they are downloaded again from MikroTik.
- An automatic backup runs every day at 04:00 (server clock). Choose how many automatic copies
to keep; backups you made or uploaded yourself are never deleted.
- Uploads must be a
.tar.gz made by SILAB; anything else is refused.
Restore replaces everything
A restore replaces every lab, the accounts and the settings with the ones in the
backup, and cannot be undone. Stop the lab first — SILAB refuses to restore while it runs — and type
RESTORE to confirm.
From the command line:
silab backup create --disks
silab backup list
System
Command line
Everything on the canvas can also be done from the server's shell with silab:
| Command | What it does |
silab image latest / pull <ver> / list | RouterOS versions from MikroTik |
silab lab load <file> / export <file> | Open a lab / save it with every router's config |
silab up / down / status | Start or stop the whole lab; routers, states, ports |
silab node reset|poweroff|cycle|wipe R1 | Power a router like a real one |
silab link down|up R1:1 | Pull or plug a cable |
silab link impair R1:1 --delay 50 --loss 2 | Make a link bad on purpose |
silab console R1 | Serial console in the terminal (Ctrl-] to leave) |
silab backup create [--disks] / list | Backups from the command line |
silab lab load ospf-basics.silab
silab up
silab link impair R1:1 --delay 50 --loss 2
silab console R1
Reference
FAQ & troubleshooting
Do I need VT-x or KVM?
Not on Linux: SILAB uses KVM when the host has it and QEMU software emulation (TCG) when it does
not. On Windows, SILAB runs inside WSL2, and WSL2 needs hardware virtualization (Intel VT-x / AMD-V)
switched on — inside a VM it must be passed through to the guest.
How many routers can I run?
Two cores and 4 GB of RAM run a handful of routers; plan about 200–300 MB of RAM per router.
Measured under software emulation, an idle router used about 220 MB and 4–6% CPU on one core. Hubs, PCs and
Internet clouds cost almost nothing.
Port 80 is already used on my server. Will SILAB break it?
No. SILAB adds its own nginx site without touching others and, when port 80 is taken — for
example by SAMM — publishes its web UI on port 8088 instead. Set SILAB_HTTP_PORT to choose another
port.
Does SILAB include RouterOS?
No. RouterOS CHR images are downloaded from MikroTik at install, after you accept MikroTik's
licence, and checksum-verified. SILAB never redistributes them. An unlicensed CHR is limited to 1 Mbps
upload per interface, which is fine for configuration labs.
Can I install SILAB on a server with no Internet access?
Yes. Install with SILAB_SKIP_IMAGE=1 and add a RouterOS image later with
silab image add followed by the image file.
The Windows installer stops and says virtualization is off.
Switch on Intel Virtualization Technology or SVM Mode in the BIOS/UEFI setup. In a VMware
virtual machine, power it off and tick Virtualize Intel VT-x/EPT or AMD-V/RVI; in Hyper-V, expose
virtualization extensions to the VM. Then run the installer again. Its log is in
%ProgramData%\SILAB\setup.log.
I installed Docker or turned on ufw and the lab lost its ports.
Run systemctl restart silab-fw, or reboot. SILAB adds narrow ACCEPT rules for the lab's
port forwards, Internet clouds and hubs where Docker or ufw would drop them, and re-adds them at every
boot.
Is SILAB free?
Yes — free to use, with no licence server and no
sign-up.
Need more help?
Email [email protected] to report a bug or
request a feature.