> ## Documentation Index
> Fetch the complete documentation index at: https://docs.edbb.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Install MikroTik CHR on your VPS

> Install MikroTik CHR from a rescue environment, configure your EDBB IP address and gateway, secure the administrator account and connect with WinBox.

MikroTik Cloud Hosted Router (CHR) runs RouterOS on your VPS. This guide uses a raw CHR disk image and a Linux rescue environment, then walks through the first network configuration.

<Warning>
  Installing CHR replaces the entire VPS disk, including the existing operating system and files. Download a backup first. Do not write the image from the running system you are replacing.
</Warning>

<span id="1-prepare-the-vps" />

<span id="prepare-the-image-and-console" />

## 1. Prepare the VPS and image

1. Check [MikroTik's CHR requirements and licence options](https://help.mikrotik.com/docs/spaces/ROS/pages/18350234/Cloud+Hosted+Router+CHR). The free licence limits upload speed to 1 Mbit/s per interface.
2. Copy your VPS's IPv4 address, prefix, gateway and DNS settings from the EDBB **Network** tab. Keep them available outside the VPS.
3. Open the [VNC console](/vps-management/enable-vnc-server), then boot a Linux rescue ISO through **Installation → ISO Boot**. See [Linux rescue](/vps-management/linux-rescue).
4. Review **Settings** for the chosen CHR release's boot requirements. CHR supports Virtio network and disk devices on KVM; do not switch to legacy drivers without a reason. Boot-mode support depends on the image/version you install.
5. Choose the intended stable CHR **raw disk image** from [MikroTik downloads](https://mikrotik.com/download). Do not choose a RouterBOARD package or a VMDK image.

<span id="2-create-the-installation-script" />

## 2. Download and extract in rescue mode

First check that the rescue environment has network access with `ip -br addr` and `ip route`. If needed, configure its interface using the IP and gateway from the panel. Changes to rescue networking do not configure RouterOS later.

Use the direct HTTPS download link for the version you selected:

```bash theme={"system"}
cd /tmp
curl --fail --location --output chr.img.zip 'PASTE_OFFICIAL_CHR_RAW_ZIP_URL'
sha256sum chr.img.zip
unzip -l chr.img.zip
```

Compare the checksum with the value published for that exact download. Check there is enough temporary space before extracting. Then run:

```bash theme={"system"}
unzip chr.img.zip
ls -lh *.img
```

Note the extracted filename, such as `chr-VERSION.img`. Do not use a different version's filename or checksum. If rescue has no Internet access, download the archive on your own computer, verify it there and transfer it into the rescue environment before extracting it.

<span id="identify-the-destination" />

## 3. Identify the destination disk

```bash theme={"system"}
lsblk -o NAME,SIZE,TYPE,FSTYPE,MOUNTPOINTS,MODEL
findmnt
```

Identify the **whole VPS disk**, such as `/dev/vda`, rather than a partition, the ISO or a temporary rescue disk. Check its size against the VPS plan and the extracted image. None of its partitions may remain mounted; unmount them and disable any swap on that disk before writing it.

Stop if you cannot clearly identify the disk. Do not choose a device only because it is first in the list.

<span id="3-run-the-installer" />

<span id="write-the-image" />

## 4. Write the image and boot from disk

Replace the image path and destination below with the values you checked. This command is destructive:

```bash theme={"system"}
sudo dd if=/tmp/chr-VERSION.img of=/dev/REPLACE_WITH_VPS_DISK bs=4M status=progress conv=fsync,nocreat
sync
```

Wait for `dd` to finish without errors. Unmount the rescue ISO in **Installation → ISO Boot**, then restart from the local disk. Watch the VNC console. If it does not boot, check the image and boot/device settings before making another disk change.

<span id="configure-routeros-manually" />

<span id="secure-the-first-login" />

## 5. Set a password and configure networking

Sign in through the console using the initial login procedure for your CHR release. Follow any first-login password prompt and choose a strong administrator password. If needed, use RouterOS's interactive `/password` command. Do not use `password` as the password.

Inspect the interface and any existing configuration:

```text theme={"system"}
/interface print
/ip address print
/ip route print
```

The following example uses `ether1` and documentation addresses. Replace the interface, address/prefix and gateway with the values from your VPS's **Network** tab. Do not add duplicate addresses or routes:

```text theme={"system"}
/ip address add address=192.0.2.10/24 interface=ether1
/ip route add dst-address=0.0.0.0/0 gateway=192.0.2.1
/ip dns set servers=1.1.1.1,1.0.0.1 allow-remote-requests=no
```

The DNS example uses public resolvers; you can use the resolver addresses shown in the panel instead. Keep `allow-remote-requests=no` unless you deliberately configure and protect a DNS service.

Check connectivity:

```text theme={"system"}
/ping 1.1.1.1 count=4
/ping example.com count=4
```

If numeric addresses work but names do not, check the DNS settings. If neither works, recheck the address, gateway and interface.

<span id="4-connect-with-winbox" />

## 6. Restrict management access and connect with WinBox

Before leaving the console, restrict management to an address or network you control. Replace `YOUR_ADMIN_IP/32` with the public address of the computer or trusted network you will connect from:

```text theme={"system"}
/ip service set winbox address=YOUR_ADMIN_IP/32
/ip service set ssh address=YOUR_ADMIN_IP/32
/ip service disable telnet,ftp,www,www-ssl,api,api-ssl
```

These are **RouterOS services inside your VPS**, not an EDBB account API. Configure an appropriate RouterOS firewall before exposing routing or VPN services. Keep console access while testing; changing your Internet connection may change the source address allowed to manage the router.

Download WinBox from [MikroTik](https://mikrotik.com/download), enter the VPS's public IP, and sign in with the account and password you set. Use IP access; local MAC discovery does not extend across the Internet.

Finally, apply the licence needed for your workload and store a RouterOS configuration backup securely outside the VPS. All traffic, including forwarded VPN traffic, remains subject to the [AUP](/acceptable-use-policy) and [SMTP policy](/faq/port-25-smtp-rate-limit-policy).
