| RouterOS Version | WAN Interface | ||
| LAN Interface | Management Subnet | ||
| SSH Port | Winbox Port |
The MikroTik Firewall Hardening generator produces ready-to-paste RouterOS firewall filter rules, service lockdowns, and Layer2 protections for RouterOS 6 and 7. It builds input and forward chain rules with established-connection handling, SSH bruteforce blacklisting, port scan detection, optional FastTrack, and a final drop for the WAN interface. The output is organized into five copyable blocks covering input, forward, address lists, services, and Layer2.
For a router with ether1 as the WAN, a bridge as the LAN, and the default 192.168.1.0/24 management subnet, keep SSH on port 2222 and Winbox on 8292. The generator emits an input chain that accepts established traffic, allows ICMP, limits SSH and Winbox to the LAN, blacklists repeated SSH attempts into ssh_blacklist, drops port scanners, and ends with a drop of all WAN input.