How to block a device by MAC address on MikroTik
Last updated: 2 October 2026
Someone is on your network who should not be, or one device is eating the line. Blocking by MAC address is the quickest way to shut a device out, and it has clear limits you should know before you rely on it.
First: find the MAC address
/ip dhcp-server lease print
/ip arp print
/ip hotspot host printThe lease list also shows the host name the device gave, which helps to tell phones apart. To see who is using the most traffic, see who is using the bandwidth.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
1. Firewall filter: no internet for that MAC
/ip firewall filter add chain=forward src-mac-address=AA:BB:CC:DD:EE:FF action=drop comment="blocked device" place-before=0place-before=0 puts the rule at the top, above FastTrack and the rule that accepts established connections, so it takes effect at once. If your filter list is empty, leave place-before=0 out.
The forward chain covers traffic through the router. To also stop the device reaching the router itself (its DNS, Winbox, the web page), add the same in the input chain:
/ip firewall filter add chain=input src-mac-address=AA:BB:CC:DD:EE:FF action=drop comment="blocked device" place-before=0Downloads that were already running under FastTrack can carry on for a short while. Clear the device's open connections to stop them now:
/ip firewall connection remove [find src-address~"192.168.88.57"]This rule only sees traffic that passes through the router. Two devices on the same switch or the same Wi-Fi can still talk to each other.
2. DHCP: give it no address
Make the lease static, then block it. The DHCP server stops answering that device:
/ip dhcp-server lease make-static [find mac-address=AA:BB:CC:DD:EE:FF]
/ip dhcp-server lease set [find mac-address=AA:BB:CC:DD:EE:FF] block-access=yesThe device loses its address when the current lease runs out. Someone who types an address in by hand gets around this, so use it together with the firewall rule. More on leases in static DHCP leases.
3. Wi-Fi: refuse the connection
On routers with the classic wireless menu, an access-list entry stops the device joining the Wi-Fi at all:
/interface wireless access-list add mac-address=AA:BB:CC:DD:EE:FF authentication=no comment="blocked device"Newer models that use the WiFi menu have an access list of their own in that menu, with a reject action. If your Wi-Fi comes from separate access points of another brand, block the device there instead.
4. Hotspot: a blocked binding
On a hotspot network, one line blocks the device completely. It does not even see the login page:
/ip hotspot ip-binding add mac-address=AA:BB:CC:DD:EE:FF type=blocked comment="blocked device"Then end its current session:
/ip hotspot active remove [find mac-address=AA:BB:CC:DD:EE:FF]
/ip hotspot host remove [find mac-address=AA:BB:CC:DD:EE:FF]The other binding types are covered in hotspot IP binding.
Which one to use
| Network | Use |
|---|---|
| Plain LAN with DHCP | Firewall rule in forward and input |
| Wi-Fi served by the MikroTik | Access list, plus the firewall rule |
| Hotspot | IP binding with type=blocked |
| PPPoE customers | Disable the customer's account, not the MAC |
Unblock
/ip firewall filter remove [find comment="blocked device"]
/ip dhcp-server lease set [find mac-address=AA:BB:CC:DD:EE:FF] block-access=no
/ip hotspot ip-binding remove [find comment="blocked device"]The limits of MAC blocking
- Random MAC addresses. Phones use a private MAC per network. "Forget this network" and joining again, or switching the private-address option, gives the phone a new MAC and your block no longer matches.
- MAC addresses can be changed on any computer in a minute.
- It blocks a device, not a person. The same person returns with another device.
So a MAC block is good for a nuisance device and for honest mistakes. To keep people out for real, change the Wi-Fi password, or make every user log in with their own name through a hotspot, where you can disable the account whatever device it is used on.
Where RadiusNest fits
With RadiusNest the thing you block is the account, not the hardware. You see who is online on every router in one list, disconnect a session with a click and disable the customer so the next login is refused on any device. A customer can also be locked to one device's MAC address, so a login cannot be passed around.
Start the free trial See pricing
Questions and answers
Does blocking a MAC address stop the device completely?
The firewall rule stops its traffic through the router. To keep it off the Wi-Fi as well, use the wireless access list or a blocked hotspot binding.
I blocked a phone and it came back. Why?
It is using a new random MAC address. MAC blocking cannot stop that; change the Wi-Fi password or require a login per user.
Can I block a device only at certain hours?
Yes. Add a time to the filter rule, for example time=22h-6h,mon,tue,wed,thu,fri,sat,sun.