MikroTik DDoS protection: what the router can stop, and what it cannot
Last updated: 11 October 2026
No rule on your router stops an attack that is bigger than your internet line: the line is full before the packets reach you. What the router can do is refuse small floods cheaply, stop scans, and never be used against others. This guide does those three things.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
1. The base: drop what is not invited
Most "attacks" on small networks are scans and password guessing against the router itself. A firewall that drops everything from the internet except replies stops them. If you have not done this yet, start with the basic firewall.
2. SYN floods
/ip settings set tcp-syncookies=yesWith SYN cookies the router answers connection attempts without keeping a record for each, so a flood of fake attempts cannot fill its memory.
3. Catch port scanners and drop them early
/ip firewall filter add chain=input in-interface-list=WAN protocol=tcp psd=21,3s,3,1 action=add-src-to-address-list address-list=scanners address-list-timeout=1d comment="port scan detection" place-before=0
/ip firewall raw add chain=prerouting in-interface-list=WAN src-address-list=scanners action=drop comment="drop scanners before connection tracking"The first rule recognises an address that tries many ports in a short time and lists it for a day. The second drops that address in the raw table, before the router spends any work tracking its connections. Raw rules are the cheapest place to drop unwanted traffic (RouterOS 6.36 and newer).
4. Limit ping to the router
/ip firewall filter add chain=input protocol=icmp limit=50,5:packet action=accept comment="ping, limited"
/ip firewall filter add chain=input protocol=icmp action=dropPlace these above your final drop rule. Ping keeps working for you, but a ping flood is cut to 50 packets a second.
5. Never answer DNS from the internet
An open DNS resolver is used to attack others: small questions with a forged sender, big answers sent to the victim. If allow-remote-requests=yes, block port 53 from outside:
/ip firewall filter add chain=input in-interface-list=WAN protocol=udp dst-port=53 action=drop place-before=0
/ip firewall filter add chain=input in-interface-list=WAN protocol=tcp dst-port=53 action=drop place-before=0The same goes for other services that answer with more than they receive: keep NTP server, SNMP and the bandwidth-test server closed to the internet.
6. Protect customers behind you
As an ISP, an attack on one customer's address still fills your shared line. Find the target:
/tool torch interface=ether1 dst-address=0.0.0.0/0Then drop traffic to that address in the raw table for a while, and ask your upstream provider to filter it before it reaches you. Only the upstream can remove an attack that fills your line.
Watch the CPU
An attack you can survive shows up as high CPU rather than a full line. See 100% CPU to find out which part of the router is busy.
Questions and answers
Can a MikroTik router stop a DDoS attack?
It can stop scans, small floods and abuse of its own services. An attack larger than your internet line has to be filtered by your upstream provider.
What is the MikroTik raw table for?
Dropping unwanted packets before connection tracking, which costs the least CPU. Use it for addresses you already know you want to block.
Should I enable tcp-syncookies on MikroTik?
Yes. It protects the router from SYN floods with almost no cost.