MikroTik firewall generator
Pick your WAN and LAN interfaces and management subnets, and get a commented RouterOS v7 firewall baseline you can review and paste.
Runs in your browser; nothing you type leaves your device
Lock-out risk. Test in a lab, or turn on Safe Mode (Ctrl+X in the terminal) before you apply this to a remote router.
Generates RouterOS v7 syntax for IPv4, with an optional IPv6 baseline. Interface and list names are checked; the script is not tested against your router, so read it before you apply it. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.
How to build a MikroTik firewall
- Enter the internet-facing interfaces (for example
ether1orpppoe-out1) and the local ones (usuallybridge). - List the subnets you manage the router from. Only they will reach WinBox and SSH, so include the address you connect from now.
- Choose the options, read the script and the notes beside it, then turn on Safe Mode (Ctrl+X in the terminal) and paste it, or download the .rsc file and import it.
What the generated firewall does
The script follows the same structure as MikroTik's own default configuration, made stricter. The input chain protects the router: it accepts packets belonging to connections already allowed, drops invalid ones, answers a limited rate of pings, lets the management subnets reach WinBox and SSH, accepts the LAN (or only DNS, DHCP, NTP and ICMP from it), and drops everything else with a final rule that has no conditions. A final unconditional drop is what turns a list of exceptions into a default-deny policy.
The forward chain protects the network behind the router. Established and related traffic is accepted (and optionally fasttracked), invalid packets are dropped, and new connections arriving from the WAN are dropped unless a destination NAT rule (a port forward) created them. That last rule is the one that stops the internet from reaching private addresses behind the router directly, which masquerade alone does not do.
Services and helpers
RouterOS listens on several management services by default. The script turns off the plain-text ones (telnet, FTP, WebFig over HTTP) and the API, and adds an address restriction to WinBox and SSH as a second layer behind the firewall. MAC Telnet, MAC WinBox and neighbour discovery work at layer 2 and ignore IP firewall rules, so they are limited to the LAN interface list. The bandwidth test server, web proxy, SOCKS and UPnP are switched off; turn back on only what you use.
Tips
- Already have a firewall? Paste your export into the MikroTik firewall auditor to see what it misses.
- Publishing a server behind the router? The port forwarding generator writes the dst-nat rules, with hairpin NAT.
- Need a block list or allow list? Build it with the address list generator.
Questions
Why is the input chain separate from the forward chain?
The input chain filters packets addressed to the router itself: WinBox, SSH, DNS, the API. The forward chain filters packets passing through it between your LAN and the internet. A router can be wide open on input while the LAN behind it is perfectly safe, which is how many MikroTik devices end up as open DNS resolvers or proxies.
Why accept established and related connections first?
Almost every packet belongs to a connection the firewall has already allowed. Accepting those in the first rule means each packet is checked once instead of walking the whole chain, and replies to the router's own DNS or NTP queries get through without extra rules. Invalid packets are dropped right after.
What does FastTrack do, and when should I turn it off?
FastTrack marks established connections so their packets skip most of the firewall, which can multiply throughput on small routers. The catch: fasttracked packets also skip simple queues, queue trees, mangle rules and IPsec policies. If you shape bandwidth per customer or use policy routing, leave FastTrack off or exclude those connections.
Will this lock me out?
It can if the computer you manage from is not in a management subnet and the LAN is not trusted. Turn on Safe Mode first (Ctrl+X in a terminal, or the Safe Mode button in WinBox): if your session drops, RouterOS undoes everything since Safe Mode started.
Can I paste this on a router that still has the default configuration?
Yes. Interface lists, list members and address-list entries are only added when missing. Without replace mode, the new rules are appended after the default ones, so the default "drop all not coming from LAN" rule may come first; review the order, or use replace mode on a router you can reach locally.
Is my configuration sent anywhere?
No. The script is assembled by JavaScript in this page. Nothing you type is uploaded, stored or logged, and the page works offline once loaded.