MikroTik firewall auditor
Paste your router's /export and get a prioritised list of common firewall and service hardening gaps, each with the line it came from and a suggested fix.
Your export is checked in your browser and never leaves your device
Optional: user accounts (/user print)
Heuristic, not a full audit. It checks common mistakes in what the export shows. A clean result doesn't prove the router is secure.
A heuristic review of one export, not a full security audit: it reads /ip firewall filter and nat, /ip service, DNS, proxy, SOCKS, UPnP, SNMP, the bandwidth test server, MAC access and users, and judges reachability from the WAN. IPv6 firewall, raw and mangle rules, scripts, wireless and VPN settings are not checked. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.
How to audit a MikroTik firewall
- In a terminal on the router, run
/export hide-sensitive(on v7/exportalready hides secrets) and copy the output, or save it with/export file=configand open the .rsc file here. - Paste it into the box. Optionally paste
/user printtoo, since exports leave users out. - Work through the findings from the top. Each shows the line it is about and a suggested fix; apply changes with Safe Mode on.
What the auditor checks
The auditor reads the menus of an export that decide how exposed a router is. In the firewall it looks for an input chain without a default deny (RouterOS accepts whatever reaches the end of a chain), missing established/related fast paths and invalid-packet drops, a forward chain that lets new WAN connections reach the LAN, accept-everything rules, and rules that can never match because an earlier rule already takes all their packets. It then works out, port by port, whether WinBox, SSH, telnet, FTP, WebFig and the API can be reached from the internet, taking each service's own address restriction into account.
Outside the firewall it flags an open DNS resolver, an enabled web proxy or SOCKS proxy (a common sign of a compromised router), UPnP, SNMP with the default community, the bandwidth test server, MAC Telnet and MAC WinBox on all interfaces, port forwards that publish RDP, SMB, databases or SSH to the whole internet, the default admin account when you paste /user print, and RouterOS versions with the 2018 WinBox credential leak.
What it doesn't check
- The IPv6 firewall, raw and mangle tables, scripts and scheduler entries, wireless security, VPN and IPsec settings, and password strength.
- Dynamic rules and services added by packages at runtime, which never appear in an export.
- Anything that depends on your network beyond the router. Fix the findings, then generate a clean baseline with the MikroTik firewall generator and compare the result with the RouterOS export diff.
Questions
Is it safe to paste my configuration here?
The export is read by JavaScript in this page and never leaves your device: there is no upload, no server-side processing, and the page's security policy blocks connections to other sites. Still, use /export hide-sensitive on v6 (v7 hides secrets by default) so passwords and keys are not in the text at all.
How does the auditor decide whether a service is exposed?
It identifies the WAN interfaces from interface lists, masquerade rules, DHCP and PPPoE clients, then walks the input chain as a new connection from the internet to the service's port would, following jumps. If an accept rule matches first, or nothing drops the packet before the end of the chain, the service counts as reachable. Rules with conditions it can't judge are counted as possibly accepting and never as dropping, so it errs toward warning you.
What does "rule can never match" mean?
An earlier rule in the same chain matches every packet the later rule would, and accepts or drops it, so the later rule never sees a packet. It is usually a rule added at the end of the chain instead of above the catch-all, which is why new rules "don't work".
Why does an open DNS resolver matter?
With allow-remote-requests=yes the router answers DNS on every interface. If the input chain doesn't drop DNS from the WAN, anyone can use it to amplify DDoS attacks, and ISPs regularly block or warn customers whose routers do.
The auditor found nothing. Is my router secure?
Not necessarily. It checks a set of common, high-impact mistakes in what an export shows. It doesn't see the firmware version's own vulnerabilities beyond a few known ones, users' passwords, scheduled scripts, or anything outside the menus listed under the tool. Keep RouterOS updated and review the rest by hand.