CheatsheetMTCNA
MikroTik Firewall Cheatsheet: Chain, Action, Connection State
15 September 2026
MikroTik Firewall Cheatsheet
Chain Overview
| Chain | Direction | Typical Use |
|---|---|---|
| input | Traffic TO router | Management access, routing protocols |
| forward | Traffic THROUGH router | LAN โ WAN, inter-VLAN, VPN passthrough |
| output | Traffic FROM router | Router-initiated connections (NTP, DNS, updates) |
Connection State
| State | Description | Typical Action |
|---|---|---|
| new | First packet of connection | Allow (with validation) / Drop invalid |
| established | Traffic in both directions seen | Accept (fast path) |
| related | Related to established (FTP data, ICMP errors) | Accept |
| invalid | Malformed, out of sequence | Drop |
Common Actions
| Action | Behavior |
|---|---|
| accept | Allow packet, stop processing |
| drop | Silently discard |
| reject | Discard + send ICMP/TCP RST |
| jump | Go to custom chain |
| return | Return from custom chain |
| passthrough | Continue to next rule (for logging/counting) |
Rule Priority (Order Matters!)
- Invalid packets โ Drop first (performance)
- Established/Related โ Accept (fast path)
- Management access โ Input chain, specific IPs
- Service rules โ Forward chain, specific ports
- Default drop โ Catch-all at end
Example: Basic Router Protection
/ip firewall filter
# 1. Drop invalid
add chain=input connection-state=invalid action=drop comment="Drop invalid"
add chain=forward connection-state=invalid action=drop
# 2. Accept established/related
add chain=input connection-state=established,related action=accept comment="Accept established"
add chain=forward connection-state=established,related action=accept
# 3. Allow management from trusted subnet
add chain=input src-address=192.168.88.0/24 protocol=tcp dst-port=22,80,443,8291 action=accept comment="MGMT access"
# 4. Allow ICMP (ping, MTU discovery)
add chain=input protocol=icmp action=accept comment="Allow ICMP"
add chain=forward protocol=icmp action=accept
# 5. Drop everything else to router
add chain=input action=drop comment="Drop all other input"
# 6. Forward: allow LAN to WAN
add chain=forward src-address=192.168.88.0/24 action=accept comment="LAN to WAN"
# 7. Default drop forward
add chain=forward action=drop comment="Drop all other forward"
NAT Quick Reference
| Type | Chain | Typical Use |
|---|---|---|
| src-nat (masquerade) | srcnat | Hide LAN behind WAN IP |
| dst-nat | dstnat | Port forwarding to internal server |
| netmap | srcnat/dstnat | 1:1 IP mapping |
# Masquerade (Internet access for LAN)
/ip firewall nat add chain=srcnat out-interface=WAN action=masquerade
# Port forward (web server inside)
/ip firewall nat add chain=dstnat dst-port=80 protocol=tcp action=dst-nat to-addresses=192.168.88.10 to-ports=80
Connection Tracking (Important for NAT/Firewall)
# View connections
/ip firewall connection print
# Connection tracking settings
/ip firewall connection tracking set enabled=yes tcp-syn-sent-timeout=5s tcp-syn-received-timeout=30s tcp-established-timeout=1d
Tips
- Use address-lists for dynamic groups (VPN clients, blocked IPs)
- Layer7 for application filtering (heavy CPU)
- FastTrack for established connections (bypass firewall, needs no queue/NAT)
- Log sparingly โ logs fill disk fast
- Test with
/tool torchor/ip firewall connection print
Download Cheatsheet Gratis
Masukkan email untuk mendapatkan link download PDF dan cheatsheet eksklusif lainnya.
Dengan mendaftar, Anda setuju menerima email dari Supono Training. Unsubscribe kapan saja.