In short: an interface list is a named group of interfaces, for example WAN or LAN. Firewall rules, neighbor discovery, and the MAC server look at the list instead of a single port: when you add a PPPoE line, an LTE connection, or a second WAN, you add it to the list and the rules apply to it immediately.
What is an interface list?
It is a label you apply to multiple interfaces. Instead of writing ether1 in every rule, you write WAN, and you decide in one single place which interfaces are “WAN”. You choose the name: RouterOS gives no special meaning to WAN or LAN; they are just names.
The lists are stored in /interface list, and the interfaces that belong to them in /interface list member:
/interface list add name=WAN
/interface list add name=LAN
/interface list member add list=WAN interface=ether1
/interface list member add list=LAN interface=bridge
The same interface can belong to multiple lists. The interface names here are from my lab: adapt them to yours.
Which lists are already on the router?
There are four predefined lists that you do not create and cannot delete (if you try, the response is cannot remove builtin): all (all interfaces), none (none), dynamic (interfaces with the dynamic flag) and static (all others). In print you recognize them by the * flag, which means “system list”.
/interface list print
/interface list member print
MikroTik’s default configuration, the one with the commented rules defconf, also creates the lists WAN and LAN: the provider-facing port in WAN, and bridge in LAN. If you reset with no-defaults=yes, those two lists are not present, and you create them manually as in Basic hardening of a MikroTik router.
none is more useful than it seems: it is the value that disables a service on all interfaces, for example /tool mac-server set allowed-interface-list=none.
How do you build a list with include and exclude?
A list can take members from other lists with include and remove them with exclude. This way you build “everything except the WAN” without listing port by port:
/interface list add name=NON-WAN include=all exclude=WAN
The order in which RouterOS calculates the list is fixed:
- adds the members of the lists in
include; - removes the members of the lists in
exclude; - adds the static members, those you put in
/interface list member.
The third point is the trap: a static member enters even if a list in exclude would have removed it. And the members coming from include and exclude do not appear in /interface list member print: there you only see the static ones.
Where are interface lists used?
Everywhere RouterOS has to decide “on which interfaces”. The places you encounter right away:
- firewall:
in-interface-listandout-interface-listin filter, NAT, mangle and raw, also with negation (in-interface-list=!LAN); - neighbor discovery:
/ip neighbor discovery-settings set discover-interface-list=LAN, the router announces itself and sees neighbors only there; - MAC server:
/tool mac-server set allowed-interface-list=LANfor MAC Telnet and/tool mac-server mac-winbox set allowed-interface-list=LANfor WinBox via MAC; - Detect Internet: it checks the interfaces in
detect-interface-listand automatically adds, as dynamic members, those that result as LAN, WAN or Internet in the lists you specify; - PPP: in the PPP profile, the parameter
interface-listadds to the list every interface created by that profile; - bridge: a list can be added as a bridge port, and from RouterOS 7.17 also in the
taggedanduntaggedfields of the VLAN table.
⚠️ Warning: Detect Internet can install DHCP client, default routes, and DNS servers. If you enable it, immediately check what it changed in the configuration.
Why use in-interface-list instead of in-interface in the firewall?
Because rules refer to the role of the interface, not its name. In the manual in-interface-list it “works like in-interface“, but on a set. The difference becomes apparent the day the network changes.
Take a router with the WAN on ether1 and the hardening firewall. The client adds a fiber line with PPPoE. With lists, you do one thing:
/interface list member add list=WAN interface=pppoe-out1
From that moment on, the masquerade out-interface-list=WAN also exits via the fiber, and the drop in-interface-list=WAN connection-nat-state=!dstnat in forward protects the LAN from that side as well. No rules to rewrite, none to duplicate.
With in-interface=ether1 you would have had to copy every rule for pppoe-out1, then for the LTE, then for the third line. More duplicate rules means more chances to forget one. And a forgotten rule is a hole.
The same applies to the other side. In the WireGuard from phone howto, the interface wg-casa enters the list LAN, and phones pass through the same rules as the home network.
Lists do not always replace in-interface. When you need to distinguish one line from another, as in load balancing with PCC on multiple internet connections, mangle marks connections per single interface. There, the exact name is required.
How do interfaces that are created and destroyed enter a list?
It depends on who creates the interface. A PPPoE client configured by you (pppoe-out1) exists in the configuration even when the line is down: you add it as a member once and it stays there.
Dynamic interfaces, however, such as those a PPPoE server creates for each connected user, appear and disappear on their own. You cannot manually add them to /interface list member. There are two ways:
- the
interface-listparameter of the PPP profile, which adds them to the list when they are created; - the default list
dynamic, to be used in rules or inside ainclude.
/ppp profile set [find name=default] interface-list=LAN
According to the manual, members added this way appear with the D (dynamic) flag in /interface list member print.
What are the typical errors?
The rule points to a list that does not exist
You copy a block of rules from another router and the name does not match: WAN versus wan, or on a reset router with no-defaults=yes the lists do not exist at all. RouterOS rejects the rule with input does not match any value of interface-list, and if the script continues, you end up with a half-configured firewall. Lists first, then rules.
You deleted a list that a rule was using
Here RouterOS does not complain: the list disappears and the rule remains, with a number instead of the name (for example in-interface-list=*2000015). It is not marked as invalid, but it no longer matches anything. Before deleting a list, check who uses it:
/ip firewall filter print where in-interface-list=NOME or out-interface-list=NOME
/ip firewall nat print where in-interface-list=NOME or out-interface-list=NOME
The new WAN port was left out
You add the second line, configure the address, the route works, but you do not add it to WAN. The masquerade does not see it, so clients cannot browse from there. And the forward drop does not protect it. Every time you add a line, the first command is the member add.
You put the port instead of the bridge
The traffic that the router forwards enters via bridge, not via ether2, which is one of its ports. If you put ether2 instead of bridge in LAN, the rule in-interface-list=LAN does not match and the LAN remains closed off from the router. For a physical port inside a bridge, the firewall has in-bridge-port, which works only if use-ip-firewall is enabled on the bridge.
Neighbor discovery works the other way around: it operates on individual ports. If the bridge is in the list, all its ports participate; if you want discovery only on specific ports, list those ports and not the bridge. The manual states this clearly: adding the bridge is not equivalent to adding all its ports, and vice versa. Details are in the MikroTik manual: Interface Lists and the MikroTik manual: Neighbor discovery.
In which how-tos do you use it?
- Basic hardening of a MikroTik router with RouterOS 7:
WANandLANlists, neighbor discovery, MAC server, and minimal firewall; - Port knocking on MikroTik: all knocks are valid only with
in-interface-list=WAN; - WireGuard VPN from phone to MikroTik: the VPN interface added to the
LANlist.
Tested in the lab on a routerboard with RouterOS 7.24.5 (stable): default lists and cannot remove builtin, list with include=all exclude= and a static member that rejoins despite exclusion (rule counters), bridge port in the list instead of the bridge (no match), rule rejected due to a non-existent list, list deleted while a rule was using it. PPPoE, PPP profile, and Detect Internet are from the documentation.
Frequently asked questions
Do WAN and LAN lists already exist on a MikroTik?
Only if the router has the default configuration. After a reset with no-defaults=yes, the default lists are only all, none, dynamic, and static: you create WAN and LAN with /interface list add.
What is the difference between in-interface and in-interface-list?
They work the same way, but in-interface-list looks at a group of interfaces. When you add an entry to the list, all rules that use it apply to that entry without modification.
Why don’t I see all members in /interface list member?
Because that command shows static members and dynamic members added by PPP or Detect Internet (flag D), but not those that the list takes from include and exclude.
Do I put the bridge or its ports in the LAN list?
For the firewall, use the bridge: forwarded traffic enters via the bridge, not the port. To limit neighbor discovery to specific ports, however, list the ports, not the bridge.



