MikroTik Network Infrastructure Architect
NIKITA TARIKIN
Complex RouterOS deployments demand specialized depth. I architect, secure, and verify them — backed by 7 active certifications, 94% average score, and zero breaches since 2015.
- LOCATION
- Da Nang, Vietnam · Remote worldwide
- HOURS
- 10:00–20:00 GMT+7
- BOOKING
- 1–2 days advance
- COMMUNICATION
- Email, Signal, Telegram, Threema or WhatsApp
On my bench: Glossema — the RouterOS 7 grammar plugin for VS Code (closed beta) · the RouterOS beeper player · free field tools →
100% POST-DELIVERY PAYMENT
No deposits. 100% post-delivery — payment triggers only when the result is verified and working.
When You Need an Expert
10+ years of financial sector trust, NDA-governed. Zero deployment failures since 2015.
Rescue Projects
Freelancer hit the budget ceiling or skill gap mid-deployment.
I complete the build, you keep the client relationship.
Shadow Warrior
Junior engineer needs invisible expert backing to protect their position.
I work behind the scenes, you take credit for successful delivery.
Enterprise Architects
Complex multi-site RouterOS deployment with zero-downtime requirement.
Secure, verified architecture. Post-payment — zero financial risk.
7 Certifications + AI = Faster, Safer Decisions
AI accelerates the work. I own the outcome.
I build grounding infrastructure that prevents hallucinations in network configuration.
RouterOS
Read-only access. Automatic rollback. Every engagement starts here.
1
:do
2
/safe-mode take on-errorunroll
3
:do
4
# Create read-only inspection account
5
:local pass :rndstr length64
6
/user add nametarikin groupread passwordpass
7
8
# Install ed25519 key — disables password auth below
9
:local sshKey ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILcHKq\
10
lDuQxD+OdfQ5ddF/o54vChHRaiDnGb7Yve7rHD nikita@tarikin.com
11
/user ssh-keys add usertarikin keysshKey
12
/ip ssh set strong-cryptoyes password-authenticationno
13
/ip service set ssh disabledno
14
15
# Open firewall before first drop rule
16
:local p /ip service get ssh port
17
/ip firewall filter add chaininput protocoltcp dst-portp \
18
src-address-listtrusted actionaccept \
19
commenttarikin onboard place-before*0
20
21
:log info onboarded tarikin (read-only, key-auth)
22
/safe-mode release
23
on-error
24
/safe-mode unroll
25
26
Deep across the stack
Each domain is graded on study and on production use.
- SecuritySecurity you can verifyI harden MikroTik RouterOS to the same standard I hold my own infrastructure to: hardware-backed keys, encrypted everything, hostile traffic dropped at the edge. Security is not a service I sell on the side.
- FirewallI find where any packet dies
- AddressingAddresses that land where you plan them
- RoutingRouting that stays up when an ISP dies
- FundamentalsRouterOS fundamentals I teach and use to rescue dead boxes
My one named frontier is carrier MPLS, VPLS and traffic engineering. I studied them in MTCINE, MikroTik's carrier-networking course, and haven't run them in production yet.
Deterministic Pricing
Limited availability: 1–2 major projects per month. Book 1–2 days ahead.
Get in touch →