To upgrade a MikroTik router from RouterOS 6 to 7, update to the latest v6 (6.49.22 as of September 2026), save a backup and an export off the router, set the update channel to upgrade and install 7.12.1, upgrade RouterBOOT, then switch to stable or long-term and install again. Plan on at least four reboots.
The mechanics are the same as any v6 point release, but the path is not. MikroTik’s updater will only offer you 7.12.1 from a v6 box, you have to run check-for-updates a second time to reach a current release, and each hop should be followed by a RouterBOOT upgrade and another reboot. The part that costs people their weekend is not the upload; it is the configuration converter, which rewrites OSPF, BGP, routing filters and PIM-SM into v7’s new menus and does not always get it right. Do it in the order below.
For a newly acquired router, use the MikroTik router setup checklist to establish management access and a recovery point before this version migration.
MikroTik upgrade from 6 to 7 in ten steps
- Check the hardware: at least 64 MB of RAM and not a MIPS-LE board.
- Update v6 to 6.49.22 on the
long-termchannel. - On 6.49.22, save an encrypted
.backupand a text/export, and copy both off the router. - Set the update channel to
upgrade: in WinBox or WebFig, System > Packages > Check For Updates, thenupgradein the Channel list. - Install 7.12.1 with Download&Install, which reboots on its own, or
/system package update install. - Run
/system routerboard upgrade(System > RouterBOARD > Upgrade in the GUI) and reboot. - Set the channel to
long-term(7.23.7) orstable(7.24.4), check for updates again and install. - Upgrade RouterBOOT and reboot once more.
- Review OSPF, BGP, routing filters, MPLS and PIM-SM by hand.
- Verify routes, firmware and clients before touching the next router.
Decide whether this box should move at all
For most routers the answer is now yes. v6 still gets patches, but MikroTik has stopped developing it: in the 6.49.21 release thread staff wrote “There is no ongoing development to v6, only critical security bugfixes” and “Do upgrade to v7 to stay safe.” The three 6.49.x builds shipped since July are compared below.
On the v7 side, 7.24.4 is the current stable and 7.23.7 is long-term, both released on 16 September 2026. The stable line is three point releases past 7.24.1 of 21 August, and the long-term channel has moved up from 7.21.5 to the 7.23 branch. endoflife.date summarises the support policy: long-term releases “receive critical bug and security fixes until the next long term release is available.” Nothing in MikroTik’s release threads says when 6.49 stops.
Can your router run RouterOS 7?
Most MikroTik hardware can, provided it has at least 64 MB of RAM and is not built on a MIPS-LE CPU. MikroTik’s Upgrading to v7 page states “We do not recommend running v7 on hardware that does not have at least 64 MB of RAM”, and the Software Specifications page rules out the MIPS-LE family, naming the RB100 series and some RB700 series devices.
Current v7 builds are published for arm64, arm, mipsbe, mmips, ppc, smips, tile and x86 on the RouterOS download page, and /system resource print tells you which one your board uses.
Flash matters as much as RAM. The community thread on v6 to v7 upgrades flags 16 MB devices such as the LHG 60G as problem cases, and one long-time poster’s advice for a network that is already working is to “just update the weaker devices to latest 6.x” and leave them there. Given MikroTik’s own “Do upgrade to v7 to stay safe”, treat that as a holding pattern for hardware that cannot move, not a plan.
Wireless is the other split. The v7 page says the newer Wi-Fi package (it still calls it wifiwave2) needs an ARM CPU and 256 MB of RAM; smaller boards stay on the legacy wireless package, which our RouterOS 7 CAPsMAN guide shows uses a different controller. A board that fails the RAM or MIPS-LE check is a replacement candidate; the hEX vs RB5009 vs CCR buying guide covers what to put in its place.
RouterOS 6.49.20 vs 6.49.21 vs 6.49.22
6.49.20 is no longer the newest RouterOS 6 build: 6.49.21 replaced it as an important security update and 6.49.22 followed. MikroTik wants the latest v6 installed before the jump, so 6.49.22 is the build to stop on.
| Build | Posted | Channel | What changed |
|---|---|---|---|
| 6.49.20 | 3 Jul 2026 | long-term, stable | ”fixed a service security issue, home user with default config not affected”; Ethernet stability on RB912 and RB911; mac-server interface-list fix |
| 6.49.21 | 3 Sep 2026 | long-term | Important security update, details withheld at release; SSH internals refactored; SNMP, btest and TFTP-client stability; tzdata2026b time zones |
| 6.49.22 | 21 Sep 2026 | long-term | ”system - improve stability” (build dated 16 Sep 2026) |
The 6.49.22 announcement gives the route: “click Check For Updates under System/Packages menu and select the long term Channel”. From the terminal:
/system package update set channel=long-term
/system package update check-for-updates
/system package update install
Backup twice, in two formats, off the router
A binary backup and a text export answer different questions, so take both. From the Backup docs:
/system backup save name=pre-v7 password=<passphrase>
Default encryption is aes-sha256; since 6.43 a backup saved without a password is stored unencrypted. The same page says “We recommend restoring the backup on the same version of RouterOS”, which means this file is your rollback to v6, not your migration vehicle.
Take a text export while the router still runs v6. Using the export command described in Configuration Management:
/export file=pre-v7
On RouterOS v6, this export includes sensitive configuration values by default; hide-sensitive produces a redacted copy. The show-sensitive option belongs to RouterOS v7 and must not be used for this pre-upgrade v6 export. Treat the unredacted .rsc file as confidential: download it and the encrypted .backup file with WinBox or SFTP before starting any upgrade, verify both downloads, and store them in encrypted storage with restricted access. Do not paste the export into a forum or public repository.
The text export omits system user passwords, installed certificates, SSH keys, Dude data and the User Manager database. Back up those items separately if needed; the v7 upgrade documentation also warns that older User Manager databases cannot migrate directly. Keep the export as a reference for reviewing the converted configuration. A backup that only exists on the flash you are about to rewrite is not a backup.
The path: latest v6, then 7.12.1, then current
MikroTik’s instruction is to first “upgrade to the latest stable or long-term release in v6”, so start by bringing the box to 6.49.22. Then, per the Upgrade manual: “if running RouterOS v6.x, even when selecting the major release upgrade channel called ‘Upgrade’, you will only see v7.12.1 as the available version. You must first upgrade to that intermediate version, and only then will newer releases be available in the channels.” 7.12.1 dates from 17 November 2023; it is a stepping stone, not a destination.
| Hop | Version | Channel | Released | Why it is there |
|---|---|---|---|---|
| Latest v6 | 6.49.22 | long-term | 21 Sep 2026 | MikroTik asks for the latest v6 before the jump |
| Intermediate | 7.12.1 | upgrade | 17 Nov 2023 | The only v7 build a v6 router is offered |
| NAND workaround, only if staging fails | 7.16.2, 7.18.2, 7.21 | manual .npk upload | various | Older flash layout cannot stage newer images |
| Destination, conservative | 7.23.7 | long-term | 16 Sep 2026 | Critical fixes only |
| Destination, current | 7.24.4 | stable | 16 Sep 2026 | New features and fixes every few months |
/system package update set channel=upgrade
/system package update check-for-updates
/system package update install
In WinBox or WebFig, plain Download under System > Packages waits for you to reboot; Download&Install reboots on its own.
After the reboot, run the bootloader step the manual calls “strongly recommended”, then reboot again:
/system routerboard upgrade
/system reboot
Switch the channel to stable or long-term, repeat check-for-updates and install, and repeat the RouterBOOT upgrade. Prefer the manual method if the box cannot reach upgrade.mikrotik.com on TCP 443: download the main routeros .npk for your architecture, drop it in the root of Files (“not inside the hotspot folder”, the manual warns) and reboot.
One more speed bump on older v7 builds. A CCR2004 thread documents the error “upgrade failed, free XXX kB disk space for a (null)upgrade” when jumping from a release older than 7.16.2 to 7.20 or later, because the old NAND layout cannot stage the larger image. The path that worked there was 7.16.2, then 7.18.2, then 7.21, with a RouterBOOT upgrade after each. If the install after 7.12.1 fails with that message, step through 7.16.2.
What the converter rewrites
The v7 page says “All known configurations will upgrade from 6.x to 7.x successfully”, and for a default-config home router that holds. Anything with routing protocols needs a line-by-line check:
- OSPFv2 and OSPFv3 merge into
/routing ospf, and “to start OSPF you need to create an instance and then add area to the instance”. The forum thread’s verdict: “The OSPF conversion is rather hit or miss as interfaces and networks are replaced with interface templates.” - BGP is a complete redesign with
connection,templateandsessionmenus. Peer roles are mandatory. - Routing filters become script-like
if .. thensyntax, and “unsupported options create empty entries”, so a filter can vanish silently. - PIM-SM configuration is not preserved.
- MPLS: “Upgrade MPLS setups with caution, and make sure to backup configuration before the upgrade.”
- One poster reports the DHCP option matcher converting to code 43 instead of 60. Check any vendor-class matching you have.
Packages change shape too. Per the Packages docs, “Most of the features are combined in one routeros package”, with wifi-qcom, wifi-qcom-ac, wireless, container, user-manager, dude, ups, zerotier and a few others as separate installs. The legacy wireless package conflicts with the Qualcomm drivers, so pick one. The LCD and KVM packages are gone in v7 altogether. MikroTik’s conversion table marks bridge and switching as converting cleanly, but verify PVIDs and tagged membership against our VLAN filtering post rather than assuming.
Can you roll back from v7 to v6?
Yes, if the router left the factory on v6. MikroTik’s Downgrading RouterOS page permits downgrades only “until the factory-installed version” and warns that going below it “can cause severe system instability or brick the device”, so a board that shipped with v7 has no v6 to return to. For the rest, the procedure is short:
- Download the v6
.npkpackages for the board’s architecture (check it with/system resource print). 6.49.22 matches the backup taken above. - Upload them to Files with WinBox, WebFig or FTP.
- Run
/system package downgrade, confirm, and let the router reboot. - Confirm the version with
/system resource print, then restore thepre-v7.backupyou saved on that same v6 build.
One documented trap for rollbacks: “If a router was downgraded to ROSv6, the configuration was modified and the router got upgraded back to ROSv7, then the resulting configuration is the one that was present before the downgrade.” Edits you make while parked on v6 will not survive a second trip to v7. The Upgrading to v7 page explains that the conversion only fires once; to re-trigger it, load a v6 backup with the force-v6-to-v7-configuration-upgrade=yes option.
When to Netinstall instead
For a 16 MB device, a box that failed mid-stage, or any router where the converter mangled OSPF, the cleaner route is the one the forum thread recommends: “Make a complete /export… nuke with netinstall, and re-config from scratch using the old export as baseline.” Netinstall “reformats the system drive, erasing all configuration and user files” while preserving the license and RouterBOOT settings, and it can install any version directly with no 7.12.1 stop. Requirements: same L2 segment as the PC, a static IP on the PC’s NIC, other interfaces disabled, and either the reset button held through power-on or /system routerboard settings set boot-device=try-ethernet-once-then-nand before the reboot. On Linux the tool is netinstall-cli, run as root.
Afterwards, import the export on v7 with /import file-name=pre-v7.rsc dry-run=yes first; dry-run “Simulates the import without making any configuration changes” and shows you exactly which v6 lines v7 rejects. Then lock the fresh box down the way our new-router hardening guide describes before it sees the WAN again. If UniFi access points hang off this router, unifiguide’s update strategy covers their side of the same problem.
Verify the v7 router before the next site
/system resource print
/system routerboard print
/routing ospf neighbor print
/routing bgp session print
/ip route print count-only
/interface wifi registration-table print
/ip dhcp-server lease print
Compare the route count against the number you recorded on v6 before the upgrade. Confirm current-firmware matches upgrade-firmware in the routerboard output. Then from a client on each VLAN: ping 1.1.1.1, dig @<gateway> example.com, and mtr -n 1.1.1.1 to prove the default route and DNS survived the conversion. Do the least important site first, and keep the pre-v7 backup until it has run clean for a week.
Related across the network
- Best Homelab Firewall in 2026: OPNsense, pfSense, UniFi, MikroTik — firewallcompare.com
- pfSense Alternatives: 7 Platforms Compared for 2026 — firewallcompare.com
Related on this site
FAQ
can i upgrade mikrotik from 6 to 7 directly?
Not through the built-in updater. A v6 router set to the upgrade channel is offered only 7.12.1, and newer v7 releases appear after that intermediate install. Netinstall is the exception: it writes any v7 version straight onto the flash, but it erases configuration and user files, so you rebuild from your export afterwards.
is routeros 6.49.20 still safe to run?
Not as a final stop. 6.49.20 fixed a service security issue in July 2026, but 6.49.21 followed on 3 September as an important security update and 6.49.22 on 21 September. MikroTik staff say v6 now gets only critical security bugfixes and advise moving to v7, so run 6.49.22 at minimum.
will my config survive the upgrade from routeros 6 to 7?
Mostly. MikroTik’s conversion table marks interfaces, bridge and switching, wireless, CAPsMAN, firewall, queues, tunnels, PPP, IPv6, HotSpot and static routing as converting cleanly. BGP, OSPF, MPLS and routing filters need manual review, PIM-SM settings are not carried over, and an older User Manager database needs /user-manager/database/migrate-legacy-db instead.
does a routeros upgrade update the routerboard firmware too?
Not unless you tell it to. RouterOS upgrades ship new RouterBOOT files, but MikroTik’s RouterBOARD docs say they “have to be applied manually”: run /system routerboard upgrade, reboot, and check that current-firmware matches upgrade-firmware. Setting auto-upgrade=yes under /system routerboard settings automates it, though the firmware still lands only after an additional reboot.
should i pick long-term or stable after 7.12.1?
Pick long-term for routers you cannot babysit, stable if you need recent features. MikroTik describes long-term as released rarely with “only the most critical fixes”, and stable as “Released every few months, including all tested new features and fixes.” As of 16 September 2026 that means 7.23.7 on long-term and 7.24.4 on stable.