Ignix is the oversight layer for RouterOS traffic-flow. The router stays the router — no subscription on the box, no replacement for WinBox, no agents on endpoints. We take the telemetry RouterOS already produces, bring it over WireGuard, and pay attention every day.
hello@ignix.co.ukOne feed. Encrypted. Metadata only. Nothing in the data path.
People pick MikroTik because RouterOS delivers serious routing capability without recurring per-device subscriptions, and because the CLI is a real operating system. Then the customer asks who is watching the network — and too often the answer is “buy a UTM instead.”
RouterOS does not charge you every year to keep routing. Ignix does not put a license on the box either. The service sits on traffic-flow. If you stop Ignix, the RB5009 is still the RB5009.
We enable traffic-flow and, optionally, DHCP syslog. We do not take WinBox away, wrap RouterOS in a proprietary overlay, or ask anyone to stop using the CLI they actually like.
IP traffic-flow is built in. WireGuard is built in on v7. DHCP syslog is built in. The missing piece is not another feature on the router — it is someone competent reading what it already emits.
When an SME wants “visibility,” the default pitch is Forti / UniFi / a licensed UTM. Ignix is the overlay that lets the MikroTik stay the edge.
Same service on every RouterBOARD that can export traffic-flow. The hardware only changes how we attach.
| Device | Typical site | How Ignix attaches |
|---|---|---|
| hEX / RB4011 | Small office | traffic-flow to a Pi or Ubuntu VM on the LAN. Router stays the router. |
| RB5009 | Professional office, multi-VLAN retail | Either the RB5009 is the WireGuard peer, or it exports to a local collector. Live in production. |
| CCR2004 / CCR2116 | Busy edge, higher flow volume | Same recipe; collector beside the CCR is the usual choice so the router is not also the tunnel endpoint for telemetry. |
| CHR | Lab / cloud | Identical path. Useful for proving the feed before a hardware cutover. |
We do not pretend every site looks the same. Both of these are live.
Multi-VLAN site. RouterOS already does DHCP, firewall, WireGuard and traffic-flow. The RB5009 is the Ignix mesh peer. Fits restaurants, retail, and any site where the MikroTik already is the network.
RouterOS
traffic-flow + WireGuard
→ Ignix EU
Professional office. MikroTik stays LAN gateway, DHCP and firewall. NetFlow lands on a small Ubuntu VM; the VM holds WireGuard. Decouples telemetry from the router as a single point of failure.
RouterOS → Ubuntu collector
WireGuard
→ Ignix EU
This is the whole on-router change for Shape B. Target address is the collector on the LAN — never a public IP.
Shape A is the same traffic-flow, with the target on the WireGuard mesh instead of a LAN VM. We do not ask sites to export NetFlow to the open internet.
If you already run RouterOS — or you sell it — this is the page to send, not the generic homepage.
hello@ignix.co.uk