TanodTools
EN

RouterOS v6 to v7 migration helper

Paste a v6 export and see it rewritten for RouterOS v7: routing tables, routing filter rules, OSPF templates and BGP connections, with a review list for everything that can't be converted mechanically.

Your export is converted in your browser and never leaves your device

Review before use. Lines marked # REVIEW need a person. Test the result on a lab router, and keep Safe Mode on (Ctrl+X) when applying it remotely.

Converts routes and route rules, routing marks, routing filters, OSPFv2, BGP peers and networks, and the NTP client; marks everything else that changed in v7 for review and passes the rest through unchanged. Be conservative: test the result on a lab router before using it. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.

How to convert a RouterOS v6 configuration to v7

  1. Run /export hide-sensitive on the v6 router (or /export file=v6 and download the file), then paste the text or open the .rsc file here.
  2. Read the converted script on the right: each converted line follows its original, shown as # v6:, and uncertain lines are commented out with a # REVIEW note.
  3. Work through the review list, then apply the result to a v7 lab router before production.

What changed between RouterOS v6 and v7

Most of a RouterOS configuration reads the same in both versions: interfaces, addresses, firewall rules, DHCP, PPP and queues keep their menus and properties. The big change is routing. v7 replaced the routing engine, and with it the way routing marks, routing filters, OSPF and BGP are configured. Routing marks are now real routing tables that must be created under /routing table with fib before routes, rules or mangle can use them, and routes say routing-table= instead of routing-mark=.

Routing filters went from one rule per match-and-action line to small scripts: /routing filter rule add chain=ospf-in rule="if (dst in 10.0.0.0/8 && dst-len in 8-24) { accept }". OSPF networks became interface templates that match interfaces by network, by name or both, with per-interface settings on the template. BGP peers became connections with explicit local.role, and advertised networks now come from an address list named in output.network.

How this helper works

  • It only rewrites what changes mechanically, shows each original line above its replacement, and leaves everything else untouched.
  • When a line can't be converted with confidence, it is commented out and explained, never guessed; the list beside the input collects them all with line numbers.
  • Compare the result with an export from the upgraded router using the RouterOS export diff, and check the firewall with the firewall auditor.

Questions

Do I need this to upgrade a router from v6 to v7?

Usually not: upgrading in place converts the configuration automatically, and MikroTik recommends that path. This helper is for seeing what will change before you upgrade, for checking what the automatic conversion did, and for rebuilding an old configuration on a new router that ships with v7.

What does it convert?

Routes with routing-mark become routes with routing-table, and every mark used by routes, rules or mangle gets a /routing table entry with fib. /ip route rule moves to /routing rule. Multi-gateway routes are split for v7 ECMP. Routing filters that match on prefix and prefix-length and set distance, local-pref, MED or AS-path prepend become /routing filter rule entries. OSPF instances, areas, networks and per-interface settings become instances, areas and interface templates. BGP instance and peer settings become connections, and BGP networks become an address list. The NTP client's servers move to the servers menu.

What doesn't it convert?

Anything it can't convert with confidence is commented out and listed for review: routing filter matchers such as BGP communities and AS paths, invert-match, OSPF virtual links and NBMA neighbours, OSPFv3, RIP, PIM, MPLS details, VRFs, BGP VPN families and uncommon peer options, User Manager, and scripts that use changed commands. It also notes behaviour changes, such as v7 rejecting routes at the end of a filter chain.

Why are some valid-looking rules commented out?

A routing filter that loses one of its conditions in translation would match more routes than it used to and could accept or drop the wrong prefixes. When any part of a rule can't be converted, the whole rule is left as a comment with the closest translation, so nothing half-converted becomes active.

Are my passwords and keys safe?

The export is converted by JavaScript in this page and never sent anywhere. Using hide-sensitive also keeps OSPF and BGP keys out of the text; put them back on the v7 router afterwards.