In short: an address list is a named list of addresses that firewall rules use instead of a hardcoded address. You add entries manually (static) or the firewall adds them automatically as traffic passes through (dynamic, usually with a timeout). This mechanism is the foundation for blacklists, port knocking, management allowlists, and domain-based filtering.

What is an address list?

It is a group of IP addresses under a common name, which filter, NAT, mangle, and raw rules can reference with a single parameter. Instead of writing ten rules, one per address, you write one rule that says “everything coming from list gestione“. Add or remove an address from the list, and the rule remains unchanged.

Each entry is a line in /ip firewall address-list: the list name (list, required) and the address (address).

How do I add static entries?

Use add, specifying the list name and the address. The address can be a single IP, a subnet, or a range:

/ip firewall address-list
add list=gestione address=192.168.88.0/24 comment="LAN"
add list=gestione address=10.255.255.0/24 comment="VPN di gestione"
add list=blacklist address=203.0.113.10 comment="Scanner visto il 2026-10-10"
add list=stampanti address=192.168.88.200-192.168.88.210

A range that matches a subnet is rewritten in CIDR notation upon saving: 192.168.0.0-192.168.1.255 becomes 192.168.0.0/23 (you can verify this with the Dojo IP calculator). IP-to-IP ranges are valid only for IPv4.

⚠️ Warning: the addresses in the examples are from my lab environment. Adapt them to your network.

What if I use a DNS name instead of an address?

The router accepts it and resolves it automatically: the entry with the name remains, and dynamic entries (flag D) appear underneath with the addresses returned by the name. This is the trick behind the howto for blocking DNS over HTTPS and DNS over TLS: dns.google brings along 8.8.8.8 and 8.8.4.4. If you then manually add 8.8.8.8 to the same list, the router responds with already have such entry.

There is also the opposite approach: an entry in /ip dns static with the parameter address-list adds to the list the addresses the router returns to devices for that domain, and removes them when the response TTL expires.

How are dynamic entries created?

A firewall rule creates them using action=add-src-to-address-list (adds the packet’s source address to the list) or action=add-dst-to-address-list (adds the destination). The list is selected with address-list, and the duration with address-list-timeout:

/ip firewall filter
add chain=input protocol=tcp dst-port=23 in-interface-list=WAN \
    action=add-src-to-address-list address-list=blacklist address-list-timeout=1d \
    comment="Chi tocca telnet va in blacklist per un giorno"
add chain=input in-interface-list=WAN src-address-list=blacklist action=drop \
    comment="Scarta la blacklist"

The point that often goes unnoticed: these two actions work in passthrough. The rule logs the address, and the packet continues to the next rules as if nothing happened. To actually block it, you need a second rule that performs drop.

If an address already in the list hits the rule again, the entry does not duplicate: it is refreshed. The manual mentions this for SSH brute-force protection. In the lab, the remaining time increased with new packets, but not always back to the full value: for a blacklist, what matters is that whoever keeps knocking remains inside, not the exact second.

How long does an entry last, and what happens on reboot?

It depends on the timeout. Reboot is the moment when the difference becomes apparent:

How the entry is created Timeout After a reboot
Manually, without timeout none persists: it is configuration
Manually, with timeout=… as specified lost: appears with the D flag, like a dynamic entry
From a rule, address-list-timeout=1h (or other time) as specified lost
From a rule, address-list-timeout=none-dynamic none lost: persists only until reboot
From a rule, address-list-timeout=none-static none persists, and is included in export and backup

none-dynamic and none-static exist only in rules (address-list-timeout): in /ip firewall address-list add the router responds invalid time value. The maximum time is 35w3d13:13:56, i.e., 21474836 seconds, slightly less than 249 days. With none-static the rule builds a list that grows forever: use it only if you know who will clean it up.

Where do I use address lists in rules?

With two parameters, src-address-list and dst-address-list, present in filter, NAT, mangle and raw. Before the name you can put ! to mean “who is not in the list”:

/ip firewall filter
add chain=input protocol=tcp dst-port=8291,22 src-address-list=gestione action=accept \
    comment="WinBox e SSH solo dalla gestione"
add chain=input protocol=tcp dst-port=22 in-interface-list=WAN \
    src-address-list=!gestione action=drop comment="SSH da fuori, se non sei in lista"

Each parameter accepts only one list. Watch out for the trap: src-address-list=A,B is accepted without errors, but it does not mean “in A and in B” nor “in A or in B”. The comma is part of the name: the rule looks for a list named exactly A,B, which usually does not exist, and therefore never matches. With ! in front it is worse: !A,B matches everything. If you need two groups, put everything in the same list or write two rules. You can, however, use source and destination together in the same rule: “from list A to list B”.

The raw table is the right place for long lists of addresses to discard in any case, because it discards in prerouting and saves connection tracking work. The manual uses it this way for bogons, with the list not_global_ipv4 of networks that cannot run on the internet:

/ip firewall raw
add chain=prerouting src-address-list=not_global_ipv4 in-interface-list=WAN action=drop \
    comment="Scarta da WAN gli indirizzi non globali"

For IPv6 the menu is /ipv6 firewall address-list: same logic, accepts an address, a prefix or a DNS name, but not IP-to-IP ranges.

How do I see what is inside a list?

With print, filtering by name. Dynamic entries have the D flag and show the time remaining before expiration:

/ip firewall address-list print where list=blacklist
/ip firewall address-list print where list~"^bussata"
/ip firewall address-list print count-only where list=blacklist
/ip firewall address-list export where list=gestione

~ compares with a regular expression, useful for viewing multiple lists together. count-only tells you only how many entries there are: it is the first thing to check on a blacklist that has been running for months. The export of a single list is available from RouterOS 7.13 and exports only static entries.

To know if the list is actually working, check the counters of the rules that use it:

/ip firewall filter print stats where comment~"blacklist"

To remove an address from all lists it ended up in:

/ip firewall address-list remove [find address=203.0.113.10]

What are they used for in practice?

  • Blacklist: anyone who touches a port that no one should touch (telnet, an escape port) ends up on the list for a day, and the router ignores them.
  • Port knocking: three lists in sequence, with timeouts of a few seconds, move the address from one knock to the next until WinBox is opened. This is the port knocking on MikroTik how-to; its trap uses the negation ! to blacklist anyone who knocks out of order.
  • Management allowlist: the networks from which you administer the router, in a single list that you use in all input rules. In the basic hardening, there are few networks and interfaces are sufficient; when the locations from which you connect become numerous, the list saves you from rewriting the rules.
  • Networks to protect: in the hotspot, the list lan-protette enumerates the networks that guests must not reach, and a script updates it when the WAN changes (protecting the LAN from hotspot clients). In multi-line balancing, the list reti-wan keeps traffic towards modem networks out of PCC (ECMP and PCC).
  • Bogon: addresses that cannot arrive from the internet (private, loopback, documentation), dropped in raw.
  • Domains: a DNS name in the list follows the service’s addresses, as for DoH servers.

You can find how they work in detail in the MikroTik manual: Address-lists as well.

What are the typical errors?

  • The name is spelled differently. Blacklist in the rule and blacklist in the list are two different lists. The router accepts the rule without protest, and the rule never finds anyone. If the counter for print stats remains at zero, compare the names letter by letter.
  • The list without the drop. add-src-to-address-list logs and lets it pass. Without a rule that drops those in the list, the blacklist fills up and blocks nothing.
  • The order of the rules. The rule that adds to the list must be above the rule that drops everything, otherwise the packet never reaches it. In multi-stage sequences (knocking, brute force), the order is part of the logic: the manual writes the SSH rules from the last stage to the first precisely for this reason.
  • The timeout is too short. With stages of one minute, the manual’s SSH protection lets 27 password attempts per minute pass. The timeout determines how heavy the rule is: too short and it stops no one, too long and it locks you out too.
  • The bogon that cuts you off. In the lab, the WAN is on 10.6.x.x/12 with gateway 10.0.0.1: if you drop from the WAN the list with 10.0.0.0/8 in raw, you lose the gateway. Remove the private networks you actually use on the WAN from the bogon list.
  • The list grows out of control. A dynamic blacklist on the internet collects thousands of addresses per day. Keep it under control with count-only and prefer finite timeouts to none-static.

⚠️ Warning: a blacklist that lists based on connections, not errors, can block you too. Put your management allowlist before the counting rules, as the manual does in SSH protection.

Tested in the lab on a routerboard running RouterOS 7.24.5 (stable): IP, subnet, range converted to CIDR, and unaligned range that remains unaligned; DNS name resolved into dynamic entries and already have such entry for an already existing address; entries from add-src-to-address-list with timeout, none-dynamic and none-static (flags and export); maximum time; rule with the wrong list name accepted without error; comma in the list name (A,B is a single name); count-only, export and remove [find address=…]; IPv6 range rejected. The behavior on reboot and the raw with bogons are from the documentation.

Frequently asked questions

What is an address list on MikroTik?

It is a named list of IP addresses in /ip firewall address-list. Filter, NAT, mangle, and raw rules check it using src-address-list or dst-address-list, so you can add or remove addresses without touching the rules.

Do address list entries survive a reboot?

Manually added entries without a timeout do. Entries with a timeout, and those created by a rule with a time or with none-dynamic, have the D flag, are not included in the export, and are lost according to the manual. Among those created by rules, only the none-static remain, as they are static and included in the export.

Can I put a domain name in an address list?

Yes: the router resolves the name and adds dynamic entries with the returned addresses under it. Do not manually add the same addresses to the same list: the router rejects them as duplicates.

Why does the rule with add-src-to-address-list not block anything?

Because it works in passthrough: it puts the address in the list and lets the packet continue. To block, you need a second rule with src-address-list= and action=drop.

Can I use two address lists in the same rule?

One for the source and one for the destination, yes. Two in the same parameter, no: src-address-list=A,B is accepted, but RouterOS reads it as the name of a single list, A,B, and the rule never matches. Merge the addresses into one list or write two rules.