For recovery on the same MikroTik router, use a password-protected binary .backup and restore it on the same RouterOS version. For inspecting or selectively moving settings, use a readable .rsc export—but do not treat it as a complete device backup. In either case, download or otherwise retrieve the file before making changes, protect it as sensitive data, and remember that saving a file is not the same as proving a recovery will work.
Choose the right backup format
| Factor | Binary system backup (.backup) |
Text export (.rsc) |
|---|---|---|
| Best suited to | Cloning configuration back onto the same router. | Reading, editing, or selectively transferring configuration. |
| Format | Binary and not intended for manual editing. | Plain-text script that can be inspected and imported. |
| What it preserves | MikroTik describes it as a binary clone of the configuration; it also stores device MAC addresses. | Exports user-edited configuration and normally omits unchanged defaults. It does not include system user passwords, installed certificates, SSH keys, The Dude data, or a User Manager database. |
| Compatibility | Restore to the same device; MikroTik recommends using the same RouterOS version as the one used to create the backup. | Match RouterOS versions where possible because commands may not exist in another version. |
| Handling sensitive information | Use a password and protect the file. A passwordless backup on RouterOS v6.43 and later is unencrypted. | With show-sensitive, the export reveals sensitive values. Treat the resulting file as confidential. |
| Official documentation | MikroTik Backup – RouterOS | MikroTik Configuration Management – RouterOS |
MikroTik summarizes the binary format this way: “System backup is the way to completely clone router configuration in binary format.” That makes it the more direct choice for same-device recovery, not the default format for moving settings to a different model.
Create and retrieve a binary backup
- Connect to the router using a management method you can use again after changes, such as WinBox or the RouterOS CLI.
- At the root prompt, save a named backup with a strong password:
/system backup save name=before-change password="<strong-password>"Replace the example password with a unique secret. Store it separately from the backup file.
- Check that the file was created:
/file print - Retrieve a copy to a separate, access-controlled location using WinBox or FTP. A file left only on the router may not help if the router or its storage becomes unavailable.
- Record the router identity and RouterOS version associated with the file, and keep the password available through an appropriate secure method.
MikroTik documentation lists aes-sha256 as the default encryption and describes RC4 as insecure and retained only for compatibility. Do not rely on an unpassworded backup for confidentiality; on RouterOS v6.43 and later, such a backup is unencrypted. The vendor’s backup documentation describes the command and restore prompts.
Restore a binary backup to the same router
Restoring replaces the active configuration with the saved state and reboots the router. Before starting, confirm that the target is the intended device, the backup belongs to it, the RouterOS version is appropriate, and you have a recoverable copy of the current state if you may need to undo the restore.
Recommended Free Tools
#1 Best Overall
- hEX also known as RB750Gr3 is a five port Gigabit Ethernet router for locations where wireless connectivity is not required
- The device has a full size USB port. This new updated revision of the hEX brings several improvements in performance
- It is affordable, small and easy to use, but at the same time comes with a very powerful dual core 880MHz CPU and 256MB RAM
- IPsec hardware encryption (~470 Mbps) and The Dude server package is supported, microSD slot on it provides improved r/w speed for file storage and Dude
- Dimensions: 113x89x28mm; Storage size: 16 MB; Passive PoE (PoE in); PCB temperature monitor, Voltage monitor and Mode button
- Place the
.backupfile somewhere RouterOS can access it, for example by uploading it through WinBox. - From the RouterOS CLI, load the file:
/system backup load name=before-change.backupUse the actual filename shown under
/file. - Provide the backup password when prompted, if applicable. Confirm the restore/reboot prompt only when ready for the router to apply the saved configuration and restart.
- After reboot, reconnect using the restored configuration and check the services and access paths you rely on.
A backup file is a recovery input, not proof of successful recovery. MikroTik recommends restoring a binary backup on the same RouterOS version; do not assume a file from one router or version is a safe migration package for another.
Create and use a readable configuration export
Use a text export when you need to inspect or selectively carry configuration. From the root prompt, create a file with:
Rank #2
- Wired Gigabit Router – 5x Gigabit Ethernet ports, 2.5G SFP, PoE-Out, USB, powered by RouterOS
/export file=configuration
RouterOS creates a readable .rsc file. You can also run /export from a particular menu to export that part of the configuration. By default, export output includes user-edited configuration rather than every unchanged default. Use show-sensitive only when the sensitive values are needed, and then protect the file accordingly.
To apply an exported script, upload or otherwise make the file accessible to RouterOS, then run:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
/import configuration.rsc
Review the script and target before importing: an export is not a full-state image. MikroTik states that exports exclude system user passwords, installed certificates, SSH keys, The Dude data, and the User Manager database. Certificates, The Dude, and User Manager data require their own export/import mechanisms; system user passwords and user SSH keys cannot be exported. For version compatibility, MikroTik recommends matching RouterOS versions during import.
Use dry-run to check script syntax
RouterOS supports an import dry-run that can catch syntax errors without changing configuration:
Rank #4
- MikroTik RouterBOARD C52iG-5HaxD2HaxD-TC-US (US Version) hAP ax (WiFi6) Quad-Core IPQ-6010 864 MHz, RAM 1GB, RouterOS, License level 4 It's time to supercharge your home network with the Generation
- hAP ax has everything you might need in a primary home access point - and more
- Forget endless reviews and comparisons - this is the perfect device for 99% of homes
- Wireless signal is now stronger than ever
- Here are the two main ingredients of hAP ax's success: a state-of-the-art dual-band, dual-chain 4-4
/import configuration.rsc verbose=yes dry-run
The scripting documentation describes this behavior in the RouterOS 7.16.x context. A successful dry-run is a syntax check only; it does not prove that the imported settings work with the target hardware, existing configuration, credentials, certificates, or network dependencies.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose a place to keep the backup
Separate local copy
Downloading the file through WinBox or FTP gives you a copy outside the router. Restrict access to the storage location, particularly for binary backups and exports containing sensitive values, and retain the password separately from a password-protected backup.
Best Value
- W128339515
Optional USB storage
A USB flash drive can provide another local copy if the router supports the device and filesystem. MikroTik’s disk documentation shows RouterOS recognizing a USB Flash Disk and describes filesystem handling. Support depends on the router, so check the documentation for your specific model and the supported filesystem before relying on USB. It is optional; WinBox or FTP retrieval does not require one.
Optional MikroTik Cloud backup
MikroTik’s RouterOS Cloud documentation describes one free backup slot per device and a 15 MB allowed backup size. It supports uploading an encrypted backup and downloading and applying it while the router can reach the MikroTik Cloud server. The documentation also describes using a secret download key to retrieve a backup from another device or location. Keep that key secret and use a strong password. These are service details in MikroTik’s documentation, not an independent guarantee of uptime or durability.
Do not confuse reset with restore
A configuration reset clears configuration and reboots the router; it is not a substitute for loading a known-good backup. RouterOS reset parameters include no-defaults and skip-backup, and the reset documentation describes an automatic backup before reset unless that behavior is skipped. Do not use skip-backup=yes casually. Before resetting, identify the target configuration state and verify that a recoverable copy exists. See MikroTik Configuration Management – RouterOS for reset and configuration-management details.
Quick Recap
What makes a backup usable for recovery?
- The file exists and has been retrieved somewhere other than the router.
- You know which router and RouterOS version it belongs to.
- You have the password needed to load an encrypted binary backup, stored separately from the file.
- You understand what the file omits: in particular, a text export does not contain system passwords, installed certificates, SSH keys, The Dude data, or User Manager data.
- You have not treated a successful save, upload, or import dry-run as a tested recovery. A recovery test requires a safe way to verify the restore without risking the live router.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

