hAP · ax era
ax palette: a solid BLUE system LED dominates at power-on; during the hold the blue goes out and the small green flashes. The cue never moved — ignore the blue.
MikroTik field tools · Fundamentals expertise · free · in-browser
I used to type this out for remote hands, hold by hold; now I send them this simulator. Pick one of six board archetypes, hold the button, and release on the LED transition — the cue that decides between backup loader, config reset, CAP mode or full wipe, and Netinstall. When someone else’s hands are at the rack, set the board up here and send the preset link; they rehearse the exact hold before touching your hardware.
Pick the board your hands are on — or load a preset link someone sent you. The deck counts with you; release on the LED transition.
field note On ax boards a solid BLUE lights first — ignore it. The cue is the small green.
hAP ax² · hAP ax³ · hAP ax lite (2022+) · Small recessed reset button — a pin, gently. Not the mode/WPS button beside it.
The trap shelf — field-earned, sourced:
hAP · ax era
ax palette: a solid BLUE system LED dominates at power-on; during the hold the blue goes out and the small green flashes. The cue never moved — ignore the blue.
hAP · ac era
ac palette: two green LEDs (pwr + usr), no blue anywhere (field). The original hAP ac (RB962) still carries a boot beeper; the ac²/ax refreshes are silent.
hAP
Dark mode looks like death
A runtime press of mode/WPS blacks out every LED by default — the board is fine.
hAP
CAP-overshoot recovery
Not another reset: connect WinBox by MAC, then QuickSet → Home AP (field).
hAP
The ax flash is late
On ARM64 boards the first green flash can arrive ~10 s after power (field).
hAP
Hidden rungs still fire
Two-rung ax manuals climb the whole ladder — the solid-LED CAP rung is real.
fleet
The LED is the command
Official pages disagree on every second-count — MikroTik’s own live manual now teaches the LED sequence. Release on the transition.
fleet
Manuals under-print the ladder
The rung count is a doc-template artifact — the field reliably reaches rungs the manual omits.
fleet
Four identities, one button
Before boot it is the ladder; on a running board it is WPS, a script hook, or a confirm-press — never a reset. 30-30-30 folklore does not apply.
fleet
The reformat hold nukes NAND
Hold ≈20 s into the reformat window and everything is irreversibly erased, RouterBOOT settings included — Netinstall becomes mandatory.
fleet
v7.17: the button says “yes”
device-mode wants a physical press to CONFIRM — a soft reboot never counts. That press is a signature, not a reset.
fleet
Two depths before power
Release at ≈3 s = boot the frozen backup loader; keep holding to LED-off = Netinstall via that loader. Two rescues, one gesture.
fleet
Netinstall’s port precondition
ether1 · ETH12 · MGMT/BOOT — by model. A server on the wrong port is the signature dead-end.
fleet
Trust the Product code
“hEX S” is two different boards; CSS326 is not CRS326. The spec-table Product code row is the resolver.
fleet
Dead buttons are usually policy
enable-jumper-reset=no kills half the button; protected-routerboot kills all of it. Check both before an RMA.
hAP ac³ numbered ladder + the generic Reset Button doc; the ax palette is field-convergent across ≥4 independent threads. Seconds are approximate and official pages disagree — the LED transition is the command. Built on a per-model table drawn from MikroTik’s manuals; check your exact SKU’s page (by Product code) before a production board.
Pick your board — or just press its button and feel the ladder.
One DC jack, one recessed reset button, and a count that starts at power-on. On ax boards the solid blue system LED is a decoy — the release cue is the small green USR LED.
field note · On ax boards a solid BLUE lights first — ignore it. The cue is the small green.
The Gr3 button is a recessed switch that shears off the PCB when you hunt for a click — press gently with a pin. The cue is an unnamed port LED on the plain hEX and the SFP LED on the hEX S.
field note · Press gently with a pin — feeling for a click tears the button off the PCB.
A PoE-fed ceiling puck makes this a two-location ceremony: power at the injector or switch port, button at the unit. The reachable center button is mode, not reset — reset hides at the cable recess behind the mounting ring.
field note · The reachable CENTER button is mode, not reset — reset hides at the cable recess.
The band digit decides what the button does: 1xx/2xx are RouterOS-only, 3xx are dual-boot, CSS is SwOS-only. On dual-boot units the flash-rung reset also boots the box into RouterOS — one-way, with no button path back to SwOS.
field note · The band digit decides everything: 1xx/2xx RouterOS-only · 3xx dual-boot · CSS = SwOS-only.
Step one is not pulling a cord but proving the board dark — redundant PSUs arbitrate highest-voltage-wins, and a forgotten feed keeps it silently alive. The LCD era announces the Netinstall rung on screen as “ether boot”; the silent ARM era gives you one USER LED.
field note · “Unplug the power” means EVERY feed — a forgotten PSU keeps the board silently alive.
Two locations: the only power switch is the PSU at the PoE injector, and the button sits under the dish’s weather cover, so the ceremony starts with a screwdriver. Overshooting to the solid rung leaves the dish with no IP — from indoors that looks dead, and it is not.
field note · Two locations: power lives at the INJECTOR, the button under the dish’s weather cover.
You almost certainly held past the flash: releasing the button on a solid LED enables CAP mode, and the board goes looking for a CAPsMAN controller it will never find. The recovery is not another reset — connect with WinBox by MAC address, then set it back through QuickSet’s Home AP mode (field). If you power-cycle and run the ceremony again, release the instant the LED starts flashing.
Dead buttons are usually policy, not hardware. Two RouterBOOT settings govern the button: enable-jumper-reset=no silently kills the config-reset half while still resetting bootloader settings, and protected-routerboot kills all of it — button, pinhole, RouterBOOT menu and Netinstall. Protected-routerboot has a tell: a steady 1-second-on, 1-second-off LED blink during the hold. Check both settings before an RMA.
Do not count seconds — release on the LED transition. Official pages disagree on every second-count (15 versus roughly 20 seconds to Netinstall, 3 versus 1–2 seconds for the backup loader), and MikroTik’s own live manual now teaches the LED sequence itself: hold through blinking, then solid, then off, and release at the rung you want. For the common config reset, release the instant the LED starts flashing.
It is a two-location ceremony: the power lives at the far end — the PoE injector or the switch port — and the button lives at the unit. Power off at the injector, hold the button at the device, re-power at the injector while still holding, and release on the LED flash. On a dish the button also sits under a weather cover, so the job starts with a screwdriver; when one pair of hands cannot span both ends, carrying the injector up to the dish works (field).
No. The reset ladder only runs when the button is held through power-on; on a running board the same button is WPS, a script hook, or a device-mode confirm-press — never a reset. The 30-30-30 folklore from consumer routers does not apply to RouterBOARD hardware. Power off first, hold, then apply power while holding.
Netinstall is the deepest rung of the reset ladder: hold until the LED goes dark and the board drops into a BOOTP wait, looking for a Netinstall server so RouterOS can be reinstalled from bare flash. The catch is a per-model port precondition — ether1 on a hEX, ETH12 on a CCR1036, the MGMT/BOOT port on a CCR2116 or an SFP-heavy CRS. A Netinstall server sitting on the wrong port is the signature dead-end.
A decoy. On ax-era boards a solid blue system LED dominates at power-on; during the hold the blue goes out and the small green USR LED starts flashing — that green flash is the release cue, never the blue. The palette is field-convergent across at least four independent threads. One timing nuance: on these ARM64 boards the first green flash can arrive around 10 seconds after power, later than on older units (field).
Because the board never went dark. Rack hardware carries redundant feeds — dual PSUs with highest-voltage-wins arbitration on a CCR, a third passive-PoE input on the CCR1009, up to five power paths on a CRS504 — so one forgotten cord or a seated hot-swap module keeps the board silently alive and the power-on ceremony never arms. On these boxes step one is not “unplug the power” but “prove it dark”: every cord, every PSU module, every injector.
You load the backup RouterBOOT boot loader — a bootloader-recovery rung, not a config reset. Holding the button before power is applied always arms the backup loader; releasing at about three seconds, while the LED is still dark, takes it cleanly. That one gesture holds two rescue depths: release early for the frozen backup loader, or keep holding to LED-off for Netinstall running through that same loader.
Almost certainly not. On a running board the mode/WPS button’s default action is dark mode: every LED off, board fully alive. On a cAP the trap is built in — the reachable center button is mode, while reset hides in the cable recess behind the mounting ring — so when directing remote hands, name the button by location, never as “the button”.
The simulator teaches the hold; the fundamentals page covers the rest of the rescue — bring-up, backup vs export, Safe Mode, Netinstall. Read RouterOS fundamentals — where competence starts, and where it ends.
Bring me the board that won’t resetAlso on the bench: Visual subnet calculator, Recursive failover simulator, Interactive packet-flow diagram, Diffie-Hellman key-exchange visualizer