RadiusNest › Guides

MikroTik basic firewall: protect the router and your network

Last updated: 2 October 2026

A MikroTik connected to the internet is scanned within minutes. These rules are the minimum every router should have: nothing from the internet reaches the router or your network unless you asked for it.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

In the examples ether1 is the internet side.

1. Protect the router itself (input)

/ip firewall filter
add chain=input connection-state=established,related action=accept comment="replies"
add chain=input connection-state=invalid action=drop
add chain=input protocol=icmp action=accept comment="ping"
add chain=input in-interface=ether1 action=drop comment="nothing else from the internet"

2. Protect the network behind it (forward)

/ip firewall filter
add chain=forward connection-state=established,related action=accept
add chain=forward connection-state=invalid action=drop
add chain=forward in-interface=ether1 connection-state=new connection-nat-state=!dstnat action=drop comment="only forwarded ports from the internet"

3. Close what you do not use

/ip service disable telnet,ftp,www,api,api-ssl
/ip service set winbox address=192.168.88.0/24
/ip service set ssh address=192.168.88.0/24

4. A real password

/user set admin password="A-long-password-here"

Better still, create a new full-rights user with another name and disable admin.

5. Limit discovery and MAC access to the LAN

/interface list add name=LAN
/interface list member add list=LAN interface=bridge
/tool mac-server set allowed-interface-list=LAN
/tool mac-server mac-winbox set allowed-interface-list=LAN
/ip neighbor discovery-settings set discover-interface-list=LAN

6. Do not be an open DNS server

If allow-remote-requests is on, the input drop rule above already blocks DNS from the internet. Never remove that rule.

Check

/ip firewall filter print
/ip service print
/log print where topics~"system,error,critical"

Lines in the log about login failures from unknown addresses mean a service is still open to the internet.

Keep it updated

Old RouterOS versions have known holes. See how to upgrade RouterOS.

Questions and answers

Will these rules cut off my own access?

Not from the LAN. Use Safe Mode while adding them; if you lose the connection the changes are undone.

Do I need the drop rule if I have NAT?

Yes. NAT hides the LAN but does not protect the router's own services.

How do I manage the router from outside safely?

Do not open Winbox to the internet. Limit it to known addresses with the address= setting on the service, or use a secure remote connection.

Related guides

Start the free trial See pricing