RouterOS export diff
Paste two exports, such as before and after a change or two routers that should match, and see exactly what differs, menu by menu.
Both exports are compared in your browser and never leave your device
Compares exports line by line within each menu, after joining wrapped lines and dropping the header. Changes in the order of rules show as removed and added lines. Secret values are masked by default. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.
How to compare two RouterOS configurations
- On each router, or before and after a change, run
/export(v6:/export hide-sensitive) and copy the output, or open the saved .rsc files. - Paste the older export on the left and the newer one on the right. The comparison updates as you type.
- Expand the highlighted sections to read what was added (+) and removed (−), and copy the changes as text for a change log.
Reading a RouterOS configuration diff
An export is the router's configuration written as the commands that would recreate it: a menu line such as /ip firewall filter followed by the add and set commands for that menu. Only settings that differ from the defaults appear, which keeps exports short but means a setting returned to its default simply disappears from the newer export. The diff treats each menu as a section, compares its commands in order, and highlights the sections that changed.
Some differences are noise rather than changes: the header with the export date, software ID and serial number is dropped, wrapped lines are joined, and comment lines can be ignored. What is left is what the router would actually do differently. Order is kept on purpose: firewall, NAT, mangle and queue rules are processed top to bottom, so moving a rule is a real change.
Tips
- Keep a dated export after every change window and compare it with the previous one to see exactly what was done.
- Checking a v6 to v7 upgrade? Compare the converted script from the migration helper with an export taken after the upgrade.
- For plain text that isn't an export, the general text diff compares word by word too.
Questions
Why compare by section instead of the whole file?
An export is a list of menus, and the same menu always appears in the same place. Comparing menu by menu keeps a change in /ip firewall filter from being mixed up with lines in /ip address, and lets you see at a glance which parts of the configuration changed.
Why do long lines from my export look different here?
RouterOS wraps long lines in an export with a backslash at the end and continues on the next line. The diff joins them back into one logical line and collapses repeated spaces, so a rule that only re-wrapped doesn't count as a change.
A rule only moved, but it shows as removed and added. Why?
Order matters in firewall, NAT and mangle chains: a rule that moves can change what the router does. The diff therefore keeps order and shows a moved rule as removed from its old position and added at the new one.
Are passwords and keys hidden?
With "Mask secrets" on, the values of passwords, secrets, private and preshared keys, MD5 keys and SNMP communities are replaced with ***** in the comparison. Either way, nothing you paste leaves your browser.
Can I use it for one export only?
Yes. With one side filled, the page lists that export's sections with their line counts, which is a quick way to read a long configuration.