Overview
Use the CHR for protecting your cloud servers using RouterOS firewall which supports Layer7 filtering, dynamic address lists and more; for running your own VPN service or monitoring network infrastructure using The Dude! It can be used as simple to deploy HTTP proxy with domain name filtering, centralized RADIUS server for AAA (Authentication, Authorization and Accounting). CHR itself can be monitored using SNMP and monitor traffic using Traffic flow. CHR can function as a DNS cache and/or static DNS for a local network. Expand the local network using BCP (Bridge Control Protocol) bridging of tunnels. Use CHR as a platform for learning networking and RouterOS at your own pace, for testing configuration before deployment in production.
Highlights
- The Dude server for monitoring network infrastructure, CAPsMAN server for rapid deployment of wireless networks.
- CHR supports IPsec, WireGuard, SSTP, L2TP, EoIP, PPTP, IPIP, OpenVPN, GRE, 6to4 and VPLS/MPLS tunnels.
- CHR can even be used for BGP peering, RIP route distribution and as an OSPF node in network.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
License can be transferred to another CHR instance. There are no refunds possible after the purchase of the license.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
RouterOS CHR 7.15.1
Additional details
Usage instructions
The default configuration provides decent security for your router. You have to use SSH RSA key to log in using SSH service on port #22 that should be set up in the firewall of the guest. From there it is possible to set up different types of access methods, HTTP/HTTPS/API/API-SSL or proprietary Winbox connection. For all these extra methods you have to secure your default user with the password before general access to the instance is allowed.
Resources
Vendor resources
Support
Vendor support
Please allow 72 hours for support to respond
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

