2.1 KiB
2.1 KiB
MikroTik Router Management Access Hardening
These commands restrict API, Winbox, and SSH access to only trusted subnets (CGNAT, VNTX public IPs, and private RFC 1918 space).
Apply to every router in the fleet. The address list is the same on all routers so the management ACL is consistent regardless of which tower you're connecting from.
1. Create the trusted address list
/ip firewall address-list
add address=204.110.188.0/22 comment="VNTX public IPs" list=trusted
add address=100.64.0.0/10 comment="CGNAT pools" list=trusted
add address=10.0.0.0/8 comment="RFC 1918 private" list=trusted
add address=192.168.0.0/16 comment="RFC 1918 private" list=trusted
2. Drop non-trusted traffic to management services
Place these at the top of /ip firewall filter chain=input (before any
existing accept rules for management ports). The place-before=0 puts them
at position 0 and 1 — adjust the number if you already have rules at the
top that must stay there.
/ip firewall filter
add action=accept chain=input comment="allow trusted to management services" dst-port=8728-8729,8291,22 protocol=tcp src-address-list=trusted place-before=0
add action=drop chain=input comment="drop untrusted to management services" dst-port=8728-8729,8291,22 protocol=tcp place-before=1
Ports covered:
8728— API (plaintext, if ever used)8729— API-SSL8291— Winbox22— SSH
3. Verify
/ip firewall address-list print where list=trusted
/ip firewall filter print chain=input where dst-port~"8728|8729|8291|22"
Notes
- The
acceptrule must come before thedroprule (lower number = earlier in the chain). - If a router already has an
acceptfordst-port=22,8291etc. without a source filter, remove it or place these new rules above it — otherwise the broad accept will match first and the drop will never fire. - IPv6 management access is not covered here. If you want the same for v6,
mirror the rules in
/ipv6 firewall filter chain=inputusing the v6 equivalents of those subnets. - After applying, test from a trusted source IP before closing the session — a misordered rule can lock you out.