MikroTik · RouterOS v7

MikroTik Torch and Packet Sniffer Commands

Quick answer #

Use Torch to see current traffic rates grouped into flows. Use the packet sniffer to inspect individual packets or save an exchange for Wireshark. Start with one interface and one question. Capturing everything is usually slower to interpret and can collect far more customer traffic than the fault requires.

Scope: RouterOS v7 on RouterBOARD, CCR, CRS running RouterOS, or CHR where the relevant feature exists. Not SwOS. Output fields depend on release and hardware. Run-time filters shown are documented in the current manual; inspect built-in help on older v7 releases. Tool access also depends on device-mode and user permissions.

Commands #

Replace bridge1, ether1 and the example client address. Run one live tool at a time and reproduce one short test. Stop Torch with Ctrl+C and sniffer quick with Q.

Live diagnostic: Torch and the sniffer can change the acceleration path and increase CPU load while running.

Commands
RouterOS v7 · RouterOS v7 terminal; absolute menu paths

Diagnostic state

Replace these example values: bridge1, 192.0.2.10/32.

/tool/torch interface=bridge1 src-address=192.0.2.10/32

Press Ctrl+C to stop Torch.

Diagnostic state

Replace these example values: bridge1.

/tool/torch interface=bridge1 ip-protocol=tcp port=443

Press Ctrl+C to stop Torch.

Read-only
/tool/sniffer/print
Output may contain sensitive operational data.
Diagnostic state

Replace these example values: bridge1, 192.0.2.10/32.

/tool/sniffer/quick interface=bridge1 ip-address=192.0.2.10/32

Press Q to stop sniffer quick.

Output may contain sensitive operational data.
Diagnostic state

Replace these example values: ether1.

/tool/sniffer/quick interface=ether1 ip-protocol=udp port=67,68

Press Q to stop sniffer quick.

Output may contain sensitive operational data.

For a short saved capture, the following starts and stops capture state and writes a file. Check existing sniffer settings first and coordinate with anyone already capturing traffic.

Commands
RouterOS v7 · RouterOS v7 terminal; absolute menu paths

Diagnostic state

Replace these example values: bridge1, 192.0.2.10/32.

/tool/sniffer/start interface=bridge1 ip-address=192.0.2.10/32

Stop with /tool/sniffer/stop after one short test.

Output may contain sensitive operational data.
Diagnostic state
/tool/sniffer/stop
Output may contain sensitive operational data.
Writes a file

Replace these example values: client-test.pcap.

/tool/sniffer/save file-name=client-test.pcap
Output may contain sensitive operational data.

Read the result #

Torch answers whether a flow is visible and how much traffic it currently carries. It does not decode an application's success. A service using TCP 443 may complete TCP while failing TLS or authentication later. The sniffer provides the packet sequence needed to separate these cases.

Choose the observation point deliberately. On the LAN side, you can usually filter on the client's private address. After source NAT, the WAN-side packet has another source. Similarly, a VLAN interface and its parent Ethernet interface expose different stages of VLAN handling. An empty capture with the wrong address filter is weak evidence.

A short capture workflow #

Write a single test statement: for example, whether the client's DNS request receives a response through this router. Pick the interface where that exchange should be visible. Inspect existing capture settings, start the narrow capture, reproduce once, stop, and save only if packet analysis is needed. Note both the start time and the interface in the incident record.

Use the result to select the next observation point. If the request arrives but no response returns, capture nearer the destination or inspect the relevant forwarding decision. Do not expand to every interface before explaining what the first capture proves.

Pitfalls and operational effect #

Torch and the sniffer can disable IP FastPath and FastTrack while running. They can therefore change load and even temporarily hide an acceleration-related problem. Keep sessions short and compare behaviour after stopping the tool.

Traffic forwarded entirely in hardware may be absent. Missing packets do not automatically mean a firewall dropped them. Torch's port filter takes one port, while the sniffer examples support a port list; do not interchange the syntax. Saved captures can contain payloads and credentials from unencrypted protocols, so handle them as sensitive operational files.

Sources

Documentation reviewed: 8 October 2026