Router automation

Your routers, on your terms

No open management ports. No passwords in scripts. A router enrolls with a one-time token, installs a small agent, and from then on it dials out to your workspace — exactly how managed networks should be built.

Enrollment

Three steps, one command

Step 1

Register in the console

Name it, choose the site and hand it an intended purpose. AetherNet issues a single-use, expiring enrollment token.

Step 2

Paste one command

The RouterOS terminal fetches a small bootstrap installer and imports it. The token is consumed on first use — it cannot be replayed.

Step 3

Verified, then managed

The console reports the router as enrolled only after the agent checks in and hardware details are discovered. Then provision.

What the router runs — sample with a one-time token
/tool fetch url="https://<your-console>/api/v1/routers/bootstrap/<one-time-token>"
mode=https dst-path="aethernet-bootstrap.rsc" check-certificate=no
:if ([:len [/file find name="aethernet-bootstrap.rsc"]] > 0) do={ /import file-name="aethernet-bootstrap.rsc" }

Provisioning

Configuration as reviewed plans — never blind scripts

Every provisioning operation is a typed plan: preview the change, review conflicts, confirm, apply, then verify by reading the result back.

Bridge & LAN

Base network setup for a new hotspot site.

DHCP & address pools

Addressing for guests without touching your core.

DNS & NTP

Sane defaults for client networks.

Hotspot server

Hotspot profile wired to your RADIUS workspace.

RADIUS client

The NAS config that lets the router talk to AetherNet.

Firewall & NAT base

The rules a healthy hotspot needs on day one.

Safety

Designed never to strand a router

  • Plans only create what is missing and record what they created — rollback is a first-class action.
  • Potentially disruptive changes require explicit confirmation with a human-readable preview.
  • Every deployment keeps a version history of what was applied and when.
  • Read-back verification after apply — the console reports what the router actually has, not what was requested.

Access model

One agent, least privilege

  • The agent runs as a dedicated, least-privilege RouterOS user — created for AetherNet alone.
  • Management traffic is router-initiated; no inbound ports are exposed by default.
  • Enrollment tokens are scoped, expiring, revocable and single-use.
  • Capability discovery records the RouterOS version and hardware so plans match the device.

Enroll a MikroTik in minutes

Bring one router during the pilot — we’ll walk the enrollment together and leave you with a managed device.