Documentation

SILAB documentation

Everything from the one-line install to your first lab, and every tool on the bench.

15 topics 4 sections Linux & Windows installers
Quick install

Labs in minutes, from one command.

On Ubuntu, run the first line as root. On Windows, run the second in PowerShell as administrator. Both verify the signed release before anything runs.

Read the full installation guide
Linux — bash
curl -fsSL https://silab.securytik.com/install.sh | sudo bash
Windows — PowerShell (not cmd)
irm https://silab.securytik.com/install.ps1 | iex

Getting started

Overview & architecture

SILAB — SecuryTik Interactive LABoratory — is a network simulation lab built for MikroTik trainers and students. Draw a topology, press start, and every router is a real RouterOS Cloud Hosted Router (CHR) you can reach with one double-click: a console in the browser, WinBox, WebFig or SSH.

Who SILAB is for

Trainers preparing a class, students practising for a MikroTik certification, and engineers who want to try a change on real RouterOS before touching production. SILAB is in the spirit of EVE-NG and PNETLab, but focused on one job and made simple.

How it works

SILAB runs on plain QEMU. When the host has KVM, SILAB uses it; when it does not — a cheap VPS, a laptop VM, a nested cloud instance — it falls back to software emulation (TCG) and still boots a router in about half a minute. Routers share one base image on disk and identical memory pages in RAM, and switches, PCs and Internet clouds cost almost nothing.

Browser→ nginx→ silab-web→ silab-engine→ QEMU + CHR per router
PartRole
silab-webThe web UI, as the unprivileged silab user, on 127.0.0.1 only behind nginx
silab-engineRoot service: routers, cables, the management network and port forwards; talks to the web over a unix socket
One QEMU per routerEach router runs in its own systemd unit with CPU and RAM caps, so one flooded router cannot freeze the host
Linkstc links between ports pass STP, LACP and LLDP; hubs, PCs and Internet NAT clouds are Linux bridges and namespaces, not VMs
Management networkIsolated, DHCP only, kept inside each router in its own VRF (vrf-mgmt)

What SILAB does

Real routers

Genuine MikroTik CHR routers and switches, cabled ether1..N exactly as drawn.

One click away

Browser console, WinBox, WebFig and SSH for every router.

Cables & power

Unplug, impair, capture; power off, reset, power cycle, wipe.

Virtual PCs

DHCP, static or PPPoE clients with ping, trace and more.

Trainer tools

Bulk actions on every router, live rename, tiny shareable labs.

Like every SecuryTik product

Signed updates, backup & restore, day and night themes.

Start with Installation, or use the menu to jump to any topic.

Getting started

Installation

SILAB installs everything it needs — QEMU, the RouterOS image, nginx and its own services — from one command. It is independent: it installs on a clean Ubuntu box and sits beside anything else already on the host without touching it.

Every install is verified: the bootstrap checks the release manifest's signature against SILAB's release key and the bundle's SHA256 before anything runs, then asks you to accept MikroTik's licence.

Pick your platform:

Installation

Linux (one command)

On Ubuntu 22.04, 24.04 or 26.04 (amd64 or arm64), run as root:

curl -fsSL https://silab.securytik.com/install.sh | sudo bash

The installer downloads from our download bucket, and from SILAB's GitHub release by itself when the bucket cannot be reached — there is nothing to choose.

What happens

  1. The bootstrap fetches the latest release manifest, checks its signature and expiry, downloads the bundle and checks its SHA256. A mismatch stops the install before anything runs.
  2. It asks you to accept MikroTik's licence for RouterOS CHR, then downloads the latest stable CHR image from MikroTik and verifies its SHA256. The image is never redistributed by SILAB.
  3. It installs QEMU, nginx and SILAB's services, and publishes the web UI on port 80 — or 8088 when port 80 is already taken, for example by SAMM.

First sign-in

Open the server in a browser and sign in:

Login URLhttp://<server>/ · Usernameadmin · Passwordadmin

Change the password right away under System → Profile. SILAB shows a warning while the default password is in use.

Unattended installs Without a terminal (cron, CI, ssh -T) the installer runs unattended. Set SILAB_ACCEPT_MIKROTIK_LICENSE=1 to accept MikroTik's licence without the prompt — see Requirements & options.

Installation

Windows (WSL2)

SILAB runs on Windows 10 (version 2004 or newer) and Windows 11 in its own WSL2 instance, set up by one installer. Open PowerShell — not Command Prompt (cmd) — and run the line below. If PowerShell is not running as administrator, Windows asks for permission: click Yes and the installation continues in a new administrator window.

irm https://silab.securytik.com/install.ps1 | iex

It downloads from our download bucket, and from SILAB's GitHub release by itself when the bucket cannot be reached.

The bootstrap downloads the full installer to %ProgramData%\SILAB\silab-windows.ps1 and runs it from there, so it can elevate itself and carry on after a restart.

What happens

  1. It enables WSL2. The first time this needs one restart of Windows; setup then continues by itself.
  2. It imports a dedicated Ubuntu 24.04 instance named SILAB (checksum-verified). Your other WSL distributions are untouched.
  3. It installs SILAB inside that instance with the Linux installer.
  4. It adds a SILAB icon to the desktop and the Start menu: a small menu to Start, Stop, see the Status, Open it in the browser, and Share on the LAN so other PCs — and their WinBox — can reach the lab.
Hardware virtualization is required on Windows Unlike Linux, WSL2 cannot run without Intel VT-x / AMD-V. On a real PC, switch on "Intel Virtualization Technology" or "SVM Mode" in the BIOS/UEFI setup. Inside a virtual machine it must be passed through to the guest — in VMware tick "Virtualize Intel VT-x/EPT or AMD-V/RVI" with the VM powered off. The installer checks this and says what to change.

Installing from a downloaded file

The full installer can also be run directly, for example from a copy on a USB stick:

powershell -ExecutionPolicy Bypass -File silab-windows.ps1

Uninstalling

-Uninstall removes the SILAB instance, the shortcut and the LAN sharing rules:

powershell -ExecutionPolicy Bypass -File "$env:ProgramData\SILAB\silab-windows.ps1" -Uninstall

Installation

Requirements & options

Requirements

  • Linux: Ubuntu 22.04, 24.04 or 26.04, amd64 or arm64, with root / sudo access. KVM is used automatically when /dev/kvm is usable; without it SILAB runs under software emulation — no VT-x needed.
  • Windows: Windows 10 version 2004 (build 19041) or newer, or Windows 11, with hardware virtualization (VT-x / AMD-V) switched on for WSL2.
  • Size: 2 cores and 4 GB of RAM run a handful of routers; plan about 200–300 MB of RAM per router.
  • RouterOS: CHR 7.15 or newer, downloaded from MikroTik.

What the installer sets up

ComponentDetails
QEMUqemu-system-x86 (or -arm on arm64 hosts) and qemu-utils; KVM used automatically when /dev/kvm is usable
RouterOS CHRLatest stable image downloaded from MikroTik after you accept MikroTik's licence; SHA256-verified
nginxPublishes the web UI on port 80 (or 8088 when 80 is taken, e.g. by SAMM) as SILAB's own site, added without touching other sites
silab-webThe web UI as the unprivileged silab user, on 127.0.0.1 only (behind nginx)
silab-engineRoot service: routers, cables, management network, port forwards
TimersDaily release check (silab-updater.timer), daily backup at 04:00 (silab-backup.timer), memory merging (silab-ksm)
NetworkingIts own bridges (sl*) and nftables table (inet silab); never touches your LAN interface
Host firewallWhere Docker or ufw drop forwarded traffic, silab-fw.service adds narrow ACCEPT rules (tagged silab) for the lab's port forwards, Internet clouds and hubs, and re-adds them at every boot
Docker or ufw added later? If you install Docker or enable ufw after SILAB, run systemctl restart silab-fw (or reboot) so the lab's rules are added again.

Environment overrides

Set these in front of the install command, e.g. curl -fsSL https://silab.securytik.com/install.sh | sudo SILAB_HTTP_PORT=8080 bash.

VariableEffect
SILAB_HTTP_PORT=NWeb UI port (default 80 when free, else 8088)
SILAB_APP_PORT=NThe app's own port on 127.0.0.1, behind nginx (default 8089)
SILAB_ACCEPT_MIKROTIK_LICENSE=1Accept MikroTik's licence without the prompt
SILAB_SKIP_IMAGE=1Offline host: install without downloading RouterOS (silab image add <file> later)
SILAB_VERBOSE=1Raw command output instead of the progress display

Getting started

Your first lab

Two routers and a cable, from an empty canvas to a ping across the link.

  1. Sign in as admin / admin and change the password under System → Profile.
  2. Create a lab, then open Lab → Topology.
  3. Click + Node and add two Router (CHR) nodes — R1 and R2 in this example.
  4. Click + Connect, click R1 then R2, and pick the ports — for example ether1 on both.
  5. Press Start lab. Under software emulation a clean two-router lab is up and provisioned in about half a minute.
  6. Double-click R1 to open its console, give ether1 an address on each router, and use Ping — click R1, then R2 — to test the cable.
One lab at a time SILAB runs one lab at a time. The labs manager creates, opens, duplicates, renames, exports and imports .silab files.

The lab file

A lab is a small YAML diagram. Exported as a .silab file it carries the diagram plus one .rsc per router — usually a few KB. The receiver's SILAB rebuilds the lab from its own RouterOS image, and imported files are validated strictly: no host paths, no raw QEMU arguments.

silab: 1
name: OSPF basics
routeros: "7.24.4"
nodes:
  - {id: 1, name: R1, kind: router, x: 100, y: 100, config: R1.rsc}
  - {id: 2, name: R2, kind: router, x: 400, y: 100}
  - {id: 3, name: LAN, kind: hub,    x: 250, y: 300}
  - {id: 4, name: PC1, kind: pc,     x: 250, y: 450}
links:
  - {a: {node: 1, port: 1}, b: {node: 2, port: 1}, delay_ms: 20}
  - {a: {node: 2, port: 2}, b: {node: 3}}
  - {a: {node: 4}, b: {node: 3}}

A lab pins its RouterOS version, so a shared lab behaves the same everywhere.

Building labs

Nodes & cables

Add nodes with + Node and cable them port to port with + Connect — while the lab runs, with no restart.

Node types

NodeWhat it is
Router (CHR)A genuine MikroTik Cloud Hosted Router. Ports are named ether1..N inside RouterOS, matching the diagram.
Switch (CHR)A CHR set up as a switch.
HubA shared segment — a Linux bridge, no VM.
PCA virtual PC: DHCP, static or PPPoE client with its own console. See Virtual PCs.
Internet (NAT)A NAT cloud that gives the lab a way out to the Internet, never onto the host's LAN.

Rename a router on the canvas and its RouterOS identity follows, live. Each router can carry a startup configuration (.rsc), applied on first boot.

Cables

  • Point-to-point cables pass every frame: STP, LACP, LLDP, MNDP and VLAN tags.
  • Unplug and plug a cable, or impair it on purpose: delay, jitter, loss, bandwidth.
  • Several cables between the same two nodes are drawn side by side, each with its own labels.
  • Right-click a cable to capture it live in Wireshark.

Power

Right-click a router for a VMware-style power menu:

ActionWhat the router sees
Power onPower applied
Shut down / RebootA clean shutdown or reboot
ResetThe reset button — no shutdown
Power off (pull the plug)Power loss: RouterOS loses exactly what a real power cut would
Power cycleUnplug and replug — also how RouterOS device-mode changes (container, traffic-gen…) are confirmed
WipeThe disk goes back to the base image
CHR free licence An unlicensed CHR is limited to 1 Mbps upload per interface. That is fine for configuration labs; keep it in mind for throughput tests.

Building labs

Reaching a router

Double-click a router for its console in the browser. It works over the router's serial port, so it keeps working even when the student has erased every IP address. Every router also gets fixed ports on the SILAB host, reachable from the LAN or the Internet.

WayWhere
ConsoleDouble-click the router → Console (browser)
WinBox<host>:20000 + id×10 — R1 is :20010
SSHssh -p <20000 + id×10 + 1> admin@<host>
WebFighttp://<host>:<20000 + id×10 + 2>

So router 1 answers WinBox on 20010, SSH on 20011 and WebFig on 20012; router 2 on 20020, 20021 and 20022. Routers log in as admin / admin.

ssh -p 20011 admin@<silab-host>

WinBox in one click

Right-click a router → WinBox and WinBox opens already connected, with the address, user and password filled in. A web page cannot start a program on your PC by itself, so this needs the WinBox helper, installed once per PC from System → Helpers:

  • Windows — download the helper, right-click it → Run with PowerShell. If it cannot find WinBox, it asks where WinBox.exe is. Restart the browser once.
  • Linux — download the helper and run sh silab-winbox-linux.sh (not as root). It finds WinBox, or asks for the path of the WinBox binary.
  • macOS — until a helper exists, right-click a router → Links → WinBox copies the address.

The helper needs no administrator rights. You need WinBox itself first, from mikrotik.com/download.

The management port

SILAB reaches each router through a management port kept in its own VRF, vrf-mgmt: out of the student's routing table and out of OSPF and BGP. The student's ports stay ether1..N, exactly as drawn.

Building labs

Virtual PCs

A PC node is a lightweight client with no VM behind it. Set its IP from the canvas — DHCP client, Static, PPPoE client (optionally only the server offering a given service name) or No address — or from its console. The console has no host shell behind it; these are its commands:

CommandWhat it does
ipShow address, gateway, DNS and mode
ip dhcpGet an address by DHCP (renews while the lab runs)
ip 192.168.88.10/24 192.168.88.1 1.1.1.1Static address, gateway and DNS (a dotted mask works too)
ip noneNo address
pppoe USER PASSWORD [SERVICE]Dial PPPoE (redials by itself); pppoe alone shows the state
ping HOST [-c COUNT | -t]Ping; -t runs until Ctrl-C
trace HOSTThe path, hop by hop (also tracert, traceroute)
nslookup NAME [SERVER]Ask DNS
web URLFetch a page as text, e.g. web http://192.168.88.1
arp · route · clear · helpNeighbour table, routes, clear the screen, the command list

Ping between any two devices

Next to + Connect on the topology, Ping tests reachability without opening a console: click two devices, five pings run in the background, and the result opens in a pop-up. SILAB pings the address on the subnet the two share, else the target's first address; an Internet node as the target pings 8.8.8.8.

Building labs

Capture in Wireshark

Right-click a cable → Capture in Wireshark: Wireshark opens on your PC and shows that cable's traffic live, in both directions, until you close it.

Install the Wireshark helper once

Like WinBox, this needs a small helper per PC, from System → Helpers. It needs no administrator rights.

  • Windows — download the helper, right-click it → Run with PowerShell. If it cannot find Wireshark, it asks where Wireshark.exe is. Restart the browser once: capture links then open Wireshark without asking.
  • Linux — download the helper and run sh silab-wireshark-linux.sh (not as root). It finds Wireshark, or asks for the path of the wireshark binary. It needs curl.

You need Wireshark itself first, from wireshark.org.

Good to know The capture runs on the SILAB server, so Wireshark needs no capture rights on your PC. Up to 4 captures run at once, and a capture link works once, within a minute.

Building labs

Bulk actions

Lab → Bulk actions makes one change on every router of the lab — or the ones you tick — and shows the result per router.

ActionWhat it does
Clock syncEvery router's clock and time zone from the SILAB host, so logs line up across the lab
NTPTurn on the NTP client with up to 4 servers
Time zoneSet a zone name such as Asia/Beirut or UTC
DNSSet the DNS servers
RouterOS commandsRun a script on every router
RouterOS upgradeRouterOS's own updater, on a chosen channel — the routers need a path to the Internet (an Internet node)
Reboot / hard reset / power cyclePower every router at once
Reset the labBack to its start

System

Updates

System → Updates shows the installed version, the latest release and What's new. A daily timer checks for new releases.

  1. Apply update downloads the signed release and checks it.
  2. It backs up the install to /var/backups/silab, swaps in the new files and restarts the engine and the web. Running routers keep running.
  3. If anything fails, the previous version is put back automatically.

After an Ubuntu release upgrade (22.04 → 24.04 → 26.04) the services rebuild SILAB's Python environment themselves on their next start; re-running the installer also works.

RouterOS versions

Several RouterOS versions can be installed side by side, and SILAB tells you when a newer RouterOS is out. Nothing updates on its own: a lab pins its version. Add one from the command line:

silab image latest
silab image pull 7.24.4
silab image list

System

Backup & restore

System → Backup & restore creates, downloads, uploads and restores backups.

  • Every backup holds every lab with its startup configs, the accounts and the settings.
  • Tick Include the routers' disks to keep their full state too — the file is larger.
  • RouterOS images are not included; they are downloaded again from MikroTik.
  • An automatic backup runs every day at 04:00 (server clock). Choose how many automatic copies to keep; backups you made or uploaded yourself are never deleted.
  • Uploads must be a .tar.gz made by SILAB; anything else is refused.
Restore replaces everything A restore replaces every lab, the accounts and the settings with the ones in the backup, and cannot be undone. Stop the lab first — SILAB refuses to restore while it runs — and type RESTORE to confirm.

From the command line:

silab backup create --disks
silab backup list

System

Command line

Everything on the canvas can also be done from the server's shell with silab:

CommandWhat it does
silab image latest / pull <ver> / listRouterOS versions from MikroTik
silab lab load <file> / export <file>Open a lab / save it with every router's config
silab up / down / statusStart or stop the whole lab; routers, states, ports
silab node reset|poweroff|cycle|wipe R1Power a router like a real one
silab link down|up R1:1Pull or plug a cable
silab link impair R1:1 --delay 50 --loss 2Make a link bad on purpose
silab console R1Serial console in the terminal (Ctrl-] to leave)
silab backup create [--disks] / listBackups from the command line
silab lab load ospf-basics.silab
silab up
silab link impair R1:1 --delay 50 --loss 2
silab console R1

Reference

FAQ & troubleshooting

Do I need VT-x or KVM?

Not on Linux: SILAB uses KVM when the host has it and QEMU software emulation (TCG) when it does not. On Windows, SILAB runs inside WSL2, and WSL2 needs hardware virtualization (Intel VT-x / AMD-V) switched on — inside a VM it must be passed through to the guest.

How many routers can I run?

Two cores and 4 GB of RAM run a handful of routers; plan about 200–300 MB of RAM per router. Measured under software emulation, an idle router used about 220 MB and 4–6% CPU on one core. Hubs, PCs and Internet clouds cost almost nothing.

Port 80 is already used on my server. Will SILAB break it?

No. SILAB adds its own nginx site without touching others and, when port 80 is taken — for example by SAMM — publishes its web UI on port 8088 instead. Set SILAB_HTTP_PORT to choose another port.

Does SILAB include RouterOS?

No. RouterOS CHR images are downloaded from MikroTik at install, after you accept MikroTik's licence, and checksum-verified. SILAB never redistributes them. An unlicensed CHR is limited to 1 Mbps upload per interface, which is fine for configuration labs.

Can I install SILAB on a server with no Internet access?

Yes. Install with SILAB_SKIP_IMAGE=1 and add a RouterOS image later with silab image add followed by the image file.

The Windows installer stops and says virtualization is off.

Switch on Intel Virtualization Technology or SVM Mode in the BIOS/UEFI setup. In a VMware virtual machine, power it off and tick Virtualize Intel VT-x/EPT or AMD-V/RVI; in Hyper-V, expose virtualization extensions to the VM. Then run the installer again. Its log is in %ProgramData%\SILAB\setup.log.

I installed Docker or turned on ufw and the lab lost its ports.

Run systemctl restart silab-fw, or reboot. SILAB adds narrow ACCEPT rules for the lab's port forwards, Internet clouds and hubs where Docker or ufw would drop them, and re-adds them at every boot.

Is SILAB free?

Yes — free to use, with no licence server and no sign-up.

Need more help?

Email [email protected] to report a bug or request a feature.