Skip to content
Topic

Firewall

Filter rules, raw, address list, port knocking, service protection: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per Safe Mode di MikroTik: come funziona la rete di sicurezza di RouterOS
Knowledge base
Knowledge base · Safe Mode

MikroTik Safe Mode: How RouterOS’s Safety Net Works

Safe Mode is RouterOS's safety net: while it is active, the router logs every change and, if the session that made them drops, it rolls them back automatically. You enable it with Ctrl+X (or F4) in the terminal and with the Safe Mode button in WinBox. It holds up to 100 actions and does not cover commands that restart the router.

8 min read
Illustrazione per Il matcher psd di MikroTik: come RouterOS riconosce le scansioni di porteKnowledge base
Knowledge base · Port scan detection

The PSD matcher in MikroTik: how RouterOS detects port scans

The PSD matcher in the RouterOS firewall detects port scans: it adds a weight for each different port touched by the same address within a short time window, and when the total reaches the threshold, the rule triggers. Usually, it places the scanner in an address list, and another rule drops it. Place it below the rules that accept legitimate traffic, and note that it does not detect slow scans.

Illustrazione per Firewall filter MikroTik: chain input, forward, output e ordine delle regoleKnowledge base
Knowledge base · Firewall filter

MikroTik Firewall Filter: input, forward, output chains and rule order

The RouterOS firewall filter directs every packet into one of three chains: input (to the router), forward (through the router), output (from the router). In each chain, rules are read from top to bottom, and the first match with an action such as accept or drop ends the processing; if no rule matches, the packet passes. For this reason, a new rule must always be placed above the final drop, never below it.

Illustrazione per Address list del firewall MikroTik: come funzionano in RouterOS 7Knowledge base
Knowledge base · Address list

MikroTik firewall address list: how they work in RouterOS 7

An address list is a named list of addresses that firewall rules use instead of a manually written address. You add the entries yourself (static) or the firewall adds them automatically as traffic passes (dynamic, usually with an expiration). This mechanism is the basis for blacklists, port knocking, management allowlists, and domain filters.

Illustrazione per Interface list MikroTik: come funzionano e perché il firewall le preferisceKnowledge base
Knowledge base · Interface list

Interface list MikroTik: come funzionano e perché il firewall le preferisce

Una interface list è un gruppo di interfacce con un nome, per esempio WAN o LAN. Le regole del firewall, il neighbor discovery e il MAC server guardano la lista invece della singola porta: quando aggiungi una linea PPPoE, una LTE o una seconda WAN, la metti nella lista e le regole valgono subito anche per lei.

Illustrazione per Bloccare DNS over HTTPS e DNS over TLS con MikroTikDojo

Blocking DNS over HTTPS and DNS over TLS with MikroTik

Encrypted DNS bypasses the router's filter: how to block DoT and DoH on RouterOS 7 using port 853, a name-based address list, the tls-host matcher, and Firefox's canary domain, all tested in the lab.

Illustrazione per Port knocking su MikroTik: WinBox si apre solo a chi bussaDojo

Port knocking on MikroTik: WinBox opens only for those who knock

The router's management port stays closed to everyone and opens for one hour only to those who touch three ports in the correct sequence. Firewall rules for RouterOS 7, three ways to knock from Linux (knock, nc, and pure bash), and how much you can trust it.

Illustrazione per Hardening di base di un router MikroTik con RouterOS 7Dojo
Howto · Security

Basic hardening of a MikroTik router with RouterOS 7

A MikroTik freshly reset with no-defaults=yes has no firewall: it is fine on the bench for learning, but it should never be put on the network like that. Before installing it, you need seven hardening steps: update RouterOS, replace the admin user, disable unused services and restrict the others to authorized addresses, close service ports on external interfaces, a minimal firewall that blocks everything coming from the internet, and a VPN for remote management.

Illustrazione per CVE-2023-47310Security
CVE-2023-47310

Bypass firewall IPv6 UDP in RouterOS 7

CVE-2023-47310 is a default configuration vulnerability in MikroTik RouterOS 7 that allows IPv6 UDP traceroute packets to bypass the firewall. It affects versions prior to 7.14. The mitigation is to update to RouterOS 7.14 or later.

Medium · 6.5
Illustrazione per CVE-2025-6443Security
CVE-2025-6443

VXLAN Vulnerability in RouterOS: CVE-2025-6443

CVE-2025-6443 is an improper access control vulnerability (CWE-284) in the VXLAN service of MikroTik RouterOS that allows a remote attacker, without authentication, to bypass access restrictions and reach internal network resources. Versions 7.15.3 and 7.16.2 are confirmed vulnerable by CVE.org, while NVD indicates all versions prior to 7.20; the exact fixed version has not yet been announced. Those using VXLAN on untrusted networks must update the firmware as soon as it becomes available and verify the service configuration.

Illustrazione per Come nascondere i router MikroTik della tua rete al tracerouteDojo
Howto · Routing

How to hide your MikroTik routers from traceroute

A traceroute launched by a client shows each router in your network, along with their addresses. By using a mangle rule that increments the TTL (action=change-ttl new-ttl=increment:1), every MikroTik router becomes invisible to traceroute, because the packet passes through it without "consuming" a hop. The rule must be limited to client traffic and applied carefully to avoid complicating troubleshooting.

Illustrazione per CVE-2019-3924Security
CVE-2019-3924

Interception vulnerability in RouterOS

CVE-2019-3924 is an interception vulnerability that allows a remote unauthenticated attacker to issue user-defined network requests to WAN and LAN clients, enabling firewall bypass or network scanning. Affected versions are long-term 6.42.11 and earlier, and stable 6.43.11 and earlier. To protect yourself, you must upgrade to a version later than those indicated.

High · 7.5
Illustrazione per CVE-2017-17538Security
CVE-2017-17538

Denial of Service via ICMP on RouterOS v6.40.5

The CVE-2017-17538 vulnerability allows a remote attacker to cause a denial of service by sending a massive sequence of ICMP packets. It affects MikroTik devices running RouterOS version 6.40.5. To mitigate the risk, you must update the firmware to a later version or apply network filters to limit ICMP traffic.