SUPONO.
CheatsheetMTCNA

MikroTik Firewall Cheatsheet: Chain, Action, Connection State

15 September 2026

MikroTik Firewall Cheatsheet

Chain Overview

Chain Direction Typical Use
input Traffic TO router Management access, routing protocols
forward Traffic THROUGH router LAN โ†” WAN, inter-VLAN, VPN passthrough
output Traffic FROM router Router-initiated connections (NTP, DNS, updates)

Connection State

State Description Typical Action
new First packet of connection Allow (with validation) / Drop invalid
established Traffic in both directions seen Accept (fast path)
related Related to established (FTP data, ICMP errors) Accept
invalid Malformed, out of sequence Drop

Common Actions

Action Behavior
accept Allow packet, stop processing
drop Silently discard
reject Discard + send ICMP/TCP RST
jump Go to custom chain
return Return from custom chain
passthrough Continue to next rule (for logging/counting)

Rule Priority (Order Matters!)

  1. Invalid packets โ€” Drop first (performance)
  2. Established/Related โ€” Accept (fast path)
  3. Management access โ€” Input chain, specific IPs
  4. Service rules โ€” Forward chain, specific ports
  5. Default drop โ€” Catch-all at end

Example: Basic Router Protection

/ip firewall filter
# 1. Drop invalid
add chain=input connection-state=invalid action=drop comment="Drop invalid"
add chain=forward connection-state=invalid action=drop

# 2. Accept established/related
add chain=input connection-state=established,related action=accept comment="Accept established"
add chain=forward connection-state=established,related action=accept

# 3. Allow management from trusted subnet
add chain=input src-address=192.168.88.0/24 protocol=tcp dst-port=22,80,443,8291 action=accept comment="MGMT access"

# 4. Allow ICMP (ping, MTU discovery)
add chain=input protocol=icmp action=accept comment="Allow ICMP"
add chain=forward protocol=icmp action=accept

# 5. Drop everything else to router
add chain=input action=drop comment="Drop all other input"

# 6. Forward: allow LAN to WAN
add chain=forward src-address=192.168.88.0/24 action=accept comment="LAN to WAN"

# 7. Default drop forward
add chain=forward action=drop comment="Drop all other forward"

NAT Quick Reference

Type Chain Typical Use
src-nat (masquerade) srcnat Hide LAN behind WAN IP
dst-nat dstnat Port forwarding to internal server
netmap srcnat/dstnat 1:1 IP mapping
# Masquerade (Internet access for LAN)
/ip firewall nat add chain=srcnat out-interface=WAN action=masquerade

# Port forward (web server inside)
/ip firewall nat add chain=dstnat dst-port=80 protocol=tcp action=dst-nat to-addresses=192.168.88.10 to-ports=80

Connection Tracking (Important for NAT/Firewall)

# View connections
/ip firewall connection print

# Connection tracking settings
/ip firewall connection tracking set enabled=yes tcp-syn-sent-timeout=5s tcp-syn-received-timeout=30s tcp-established-timeout=1d

Tips

  • Use address-lists for dynamic groups (VPN clients, blocked IPs)
  • Layer7 for application filtering (heavy CPU)
  • FastTrack for established connections (bypass firewall, needs no queue/NAT)
  • Log sparingly โ€” logs fill disk fast
  • Test with /tool torch or /ip firewall connection print

Download Cheatsheet Gratis

Masukkan email untuk mendapatkan link download PDF dan cheatsheet eksklusif lainnya.

Dengan mendaftar, Anda setuju menerima email dari Supono Training. Unsubscribe kapan saja.