Skip to main content

Documentation updates - September 28, 2026

Summary of documentation changes made on September 28, 2026.

Firewall & QoS​

  • UPnP: Rewritten and verified against RouterOS 7.25. Corrected the allow-disable-external-interface default (it is no), renamed forced-external-ip to forced-ip, removed the outdated step of enabling new interface entries (they are created enabled), and documented that several external interfaces can serve mappings in parallel, each advertised as its own WAN connection device. Added technical details: the service ports (SSDP on UDP 1900, control on TCP 2828 of internal interface addresses), that only permanent mappings are accepted, and that any settings change removes all dynamic port mappings.
  • NAT-PMP: Rewritten following RFC 6886. Corrected the port description (the service listens on UDP 5351, clients listen for the external address announcements on UDP 5350), documented that only one external interface is accepted, and replaced the example output with text (the old port mapping comment could not have come from a NAT-PMP request, which carries no description field).
  • SSH brute-force protection: Rewritten with a rule set that works in the default firewall; the old rules were placed after the default drop rule and had no drop rule of their own. Added trusted addresses, unblocking and how many password guesses the rules still allow.
  • Port knocking: The knock rules now go before the default drop rule, and the broken passphrase (layer 7) example was rebuilt with a working client.
  • DDoS protection: Explained how the detection works and where it stops helping. Removed the SYN-ACK rule, which never matched, and the list-creation lines, which left a 0.0.0.0 entry.

Getting Started​

  • Securing your router: Corrected commands and claims: the sample password contained a non-Latin letter, $ must be escaped in passwords, the WAN firewall example now works with the default configuration, available-from replaces the deprecated address, and the strong-crypto description was wrong.

High Availability Solutions​

  • MLAG: Described the values of mlag-state.

CLI Reference​

  • /ip/upnp, /ip/upnp/interfaces, /ip/nat-pmp, /ip/nat-pmp/interfaces: Filled in all parameter descriptions, including defaults, the effect of forced-ip, and the ForceTermination behavior of allow-disable-external-interface.
  • CLI Reference: Removed parameters that RouterOS no longer has from about 40 command pages, for example in /disk, /system/health and /lcd, and marked deprecated parameters.