How to block or limit torrents on MikroTik: what really works
Last updated: 11 October 2026
Torrent software opens hundreds of connections and can fill a line by itself. Many guides promise a rule that blocks it completely. None of them do: modern torrent traffic is encrypted and uses random ports. What does work is making torrents harmless to everyone else.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
1. Fair sharing first
The most effective step is not about torrents at all. With PCQ or a limit per user, a torrent user can only fill their own share. Everyone else keeps browsing at full speed. If every customer already has a speed limit, torrents mostly hurt the person running them.
2. Limit connections per user
Torrents are recognisable by their number of connections. Cap new TCP connections per address:
/ip firewall filter add chain=forward src-address=192.168.88.0/24 protocol=tcp tcp-flags=syn connection-state=new connection-limit=200,32 action=drop comment="max 200 TCP connections per user"200,32 means: more than 200 connections from one address (/32) and new ones are dropped. Normal browsing, video and games stay far below 200. If someone runs a legitimate busy service, raise the number or exclude that address. Put the rule above any rule that accepts forward traffic.
3. Block tracker and torrent sites
Torrent clients first ask trackers and torrent sites. Blocking their names by DNS, as in how to block websites, stops many downloads from starting. It is not complete, because clients also find peers without trackers.
4. Find who is doing it
/ip firewall connection print count-only where src-address~"192.168.88.50"
/tool torch interface=bridge src-address=0.0.0.0/0 port=anyOne address with hundreds of connections to many different addresses and high ports is almost always a torrent client. See who is using the bandwidth.
What not to rely on
- Layer 7 patterns: they read the first bytes of each connection. Encrypted torrent traffic does not match, and the patterns cost a lot of CPU on a busy router.
- Blocking port 6881: modern clients use random ports.
- The p2p matcher: made for protocols of many years ago; it misses today's traffic.
Put it in your terms
Tell customers in your terms of service that file sharing is limited, and enforce it with speed and connection limits rather than an arms race of blocking rules.
Questions and answers
Can MikroTik block torrents completely?
No. Encrypted torrent traffic on random ports cannot be recognised reliably. Limit its effect with per-user speed limits and a connection limit instead.
How many connections per user should I allow?
Around 150 to 300 TCP connections per address leaves normal use untouched and stops most torrent clients from flooding the line.
Does layer 7 blocking work for torrents?
Poorly. Encrypted traffic does not match, and layer 7 uses a lot of CPU.