Commands #
The first three commands read device identity and version information. The export and backup commands create files. Replace the password placeholder with a unique secret in your private administrative session; do not paste a real password into a shared ticket.
Commands
RouterOS v7 · RouterOS v7 terminal; absolute menu paths
/system/identity/print/system/resource/print/system/package/printReplace these example values: before-change.
/export file=before-changeOutput may contain sensitive operational data.Replace these example values: REPLACE_WITH_UNIQUE_SECRET, before-change.
/system/backup/save name=before-change password="REPLACE_WITH_UNIQUE_SECRET"Output may contain sensitive operational data./file/print/system/history/print detailChoose the right artefact #
The .rsc export is readable configuration text. RouterOS normally hides sensitive values in export output, and the default compact export omits unchanged defaults. That makes the file useful for change review, but it also means it should not be mistaken for an inventory of every effective setting or credential.
A binary .backup is intended for recovery of the router configuration. Explicitly set a password when creating it. Keep it with the exact device and software-version record, then download it to controlled storage. A backup left only on the router is not sufficient protection against losing that router.
Text export does not include every component needed for a replacement system, such as installed certificates and all authentication material. Identify those dependencies in the recovery plan. Do not discover them for the first time after replacing failed hardware.
Safe Mode workflow #
Before changing a remote access dependency, open an independent recovery path where possible and confirm the backup files have been downloaded. In the RouterOS terminal, press Ctrl+X to enter Safe Mode and verify that the prompt shows its active state. Make a small, coherent change and test the result from the affected path.
If the result is correct, press Ctrl+X to release Safe Mode and keep the changes. Ctrl+D discards Safe Mode changes. Unexpected session loss can trigger rollback after a timeout; it is not necessarily immediate. Do not assume /quit performs the same discard operation.
Pitfalls #
Safe Mode can track changes from other sessions too, and its history capacity is limited. Exceeding the available history can release Safe Mode and remove automatic rollback protection. Safe Mode also does not protect reset or restore operations that require a reboot. Coordinate with other administrators and work in small batches rather than pasting a large configuration. A retained management session also does not prove that every client service survived the change.
Treat exports as sensitive even when secret values are hidden: addresses, usernames, customer names and comments still describe the network. Verify download integrity and keep recovery instructions alongside the files. A restore is an operational change with possible reboot and compatibility consequences, so it is deliberately not a copy-button action on this reference page.
Sources
Documentation reviewed: 8 October 2026