MikroTik CHR is available as a ready-made KVM Template — there is no need to install it from the console.
Requirements
- at least one public IPv4 address
- at least one virtual network for the LAN side
Creating the virtual machine
- Under Create New Virtual Machine, go to the KVM Templates tab and select the version of MikroTik-CHR you want.
- Recommended sizing: 1 vCPU, 512 MB RAM. The default boot disk with 10 GB is enough.
- Under Virtual Networks, add the network interfaces you need — typically one per zone, e.g. WAN, LAN and DMZ. The order of the interfaces decides which interface gets which number in RouterOS.
MikroTik CHR is barely secured in its default state: the user admin has no password, and the management services are open. So set up firewall rules in the Client Area that limit access to your own addresses before you connect the VM to the internet.
First sign-in
Open the VNC Console and sign in with the user admin and an empty password. First of all, set a password:
/user set admin password=<your password>
Then disable the services you do not need and restrict the remaining ones to your networks:
/ip service disable telnet,ftp,api,api-ssl
/ip service set winbox,ssh,www-ssl address=<your network>
Everything else is described in the MikroTik documentation.