Skip to main content
Version: 7.25

Services

The /ip/service menu lists the services the router offers for management and access: WinBox, SSH, Telnet, FTP, the web server, the API and the reverse proxy. Each service has a port, the addresses and the VRF it accepts clients from, and, for the TLS services, a certificate. You cannot add services, only change, disable and enable the existing ones.

The same menu also shows dynamic entries: the ports that other features and containers listen on, and the connections that are open to the router's services. Use the list to see which ports are open on the router and what the firewall has to allow or block.

For advice on which services to disable, how to change the SSH port and how to protect management access with the firewall, see Securing your router.

ServiceDefault portUsed for
ftp21FTP file transfer to and from the router's storage
ssh22SSH access
telnet23Telnet access
www80The web server over HTTP: WebFig, the REST API and graphs
www-ssl443The web server over HTTPS; needs a certificate, see Enable HTTPS
winbox8291WinBox, the MikroTik mobile app and The Dude
api8728The API
api-ssl8729The API over TLS
reverse-proxy443The reverse proxy; listens only while at least one enabled rule exists

See what the router listens on​

Dynamic entries show the ports that RouterOS features and containers listen on, and the open connections to the router's services:

/ip/service/print where dynamic
Flags: D - DYNAMIC; c - CONNECTION
Columns: NAME, PORT, PROTO, LOCAL, REMOTE
# NAME PORT PROTO LOCAL REMOTE
3 Dc ssh 22 tcp 192.168.88.1 192.168.88.10:53163
4 D resolver 53 tcp
5 D resolver 53 udp
0 D btest 2000 tcp
1 D discover 5678 udp
2 D cloud 54103 udp
  • Entries with only the D flag are ports a feature listens on. NAME is the feature or program, for example resolver for the DNS server, btest for the bandwidth test server, discover for neighbor discovery and cloud for the local port the MikroTik cloud services use to talk to the cloud servers.
  • Entries with the c flag are open connections to a service. LOCAL is the router's address and REMOTE is the client's address and port.
  • Ports that containers listen on also show the NETNS and CONTAINER columns: the network namespace and the name of the container.

An entry appears when a feature starts to listen. For example, the resolver entries on port 53 appear when you set allow-remote-requests=yes in /ip/dns. The router accepts connections on the ports of the dynamic entries and of the enabled services (the entries without the X flag in /ip/service/print). IP protocols without ports, such as GRE or OSPF, are not in the list; the tables at the end of this page list them. The ports where a feature waits for clients, such as resolver or btest, are the ones the firewall input chain has to allow for the clients that need them and block for everyone else; the default firewall already drops connections to them from the internet. You cannot change dynamic entries in /ip/service; change or disable the feature in its own menu instead.

Limit who can use a service​

To accept WinBox and SSH connections only from the LAN and from VPN clients:

/ip/service/set winbox,ssh available-from=192.168.88.0/24,10.8.0.0/24
/ip/service/print proplist=name,port,available-from where !dynamic
Flags: X - DISABLED, I - INVALID
Columns: NAME, PORT, AVAILABLE-FROM
# NAME PORT AVAILABLE-FROM
6 ftp 21
7 ssh 22 192.168.88.0/24
10.8.0.0/24
8 telnet 23
9 www 80
10 X www-ssl 443
11 reverse-proxy 443
12 winbox 8291 192.168.88.0/24
10.8.0.0/24
13 api 8728
14 api-ssl 8729

available-from takes a list of IPv4 and IPv6 prefixes, for example 10.5.101.0/24,2001:db8:fade::/64. An empty list means any address. A list with only IPv4 prefixes refuses all IPv6 clients; add the IPv6 prefixes that need access.

warning

Include the address you manage the router from. After the change, the router refuses new connections from other addresses, including your own next login if it comes from outside the list.

A client from another address can still open the TCP connection, and the router then closes it without serving the client, so a port scan still finds the port open. available-from suits restricting access within trusted networks. To block access from the internet and other untrusted networks, drop the traffic in the firewall input chain, as described in Securing your router.

Run management services in a VRF​

A management VRF keeps management access apart from the networks the router serves. To make WinBox and SSH available only through a dedicated management port, ether5, which has the management address (for example 10.99.0.1/24):

/ip/vrf/add name=mgmt interfaces=ether5
/ip/service/set winbox,ssh vrf=mgmt

A service listens only in its VRF. After this change, the router refuses WinBox and SSH connections to its addresses in the main routing table and serves them only through ether5. For more about VRFs, see VRF.

warning

After the change, WinBox and SSH are reachable only through the interfaces of the VRF. A session that comes in through another interface, or through ether5 before it joins the VRF, is cut. Run both commands together, connect again through ether5, and keep another way in, such as MAC WinBox.

Manage services in WinBox​

Open IP > Services. The list can also show dynamic listeners and active connections; open the configurable service row, such as winbox, rather than a dynamic connection entry. Use Find to locate the service by name.

  1. Check Port in the service dialog. Changing it changes the port clients must use to connect.
  2. Use the + control beside Available From to enter the client addresses or subnets that should have access, then select OK. Include the address of your management computer before restricting the service you are connected through. An empty list does not restrict client addresses.

WinBox IP Service dialog for the winbox service

To turn an unused service off without changing its port, select its row in the Services list and select Disable. Select Enable to turn it on again.

Web server​

The web server has separate settings for its parts: the home page, WebFig, graphs, the REST API, and the CRL, SCEP and ACME endpoints. The -plain settings control HTTP connections (the www service), and the -secure settings control HTTPS connections (the www-ssl service). All parts are enabled by default. For the settings, see the /ip/service/webserver CLI reference.

Protocols and ports​

The following tables list the ports and IP protocols that RouterOS uses. Most ports are ones the router listens on when the feature is enabled. Some are client ports: the DHCP client receives replies on UDP port 68, and the DHCPv6 client on UDP port 546. The FTP server does not listen on TCP port 20: in active mode, its data connections come from that port. For OpenFlow, the router connects to the controller at the address and port set in controllers in /openflow, for example TCP port 6653, and does not listen on a port.

TCP ports​

PortUsed by
21FTP (ftp service)
22SSH (ssh service)
23Telnet (telnet service)
53DNS server, when allow-remote-requests=yes
80HTTP (www service)
179BGP
443HTTPS (www-ssl service) and the reverse proxy (reverse-proxy service)
646LDP transport session
1080SOCKS proxy
1194OpenVPN server
1723PPTP server
2000Bandwidth test server
2828UPnP control, on the internal interfaces
5246CAPsMAN for WiFi
8080Web proxy, default port
8291WinBox (winbox service)
8728API (api service)
8729API over TLS (api-ssl service)

UDP ports​

PortUsed by
53DNS server, when allow-remote-requests=yes
67DHCP server
68DHCP client (client port)
69TFTP server
123NTP server
161SNMP
500IKE for IPsec
520RIP
521RIPng
546DHCPv6 client (client port)
547DHCPv6 server
646LDP hello messages
1701L2TP
1900UPnP discovery (SSDP), on the internal interfaces
3799RADIUS incoming requests (CoA and disconnect)
4500IPsec NAT traversal
5246CAPsMAN control, for WiFi and for legacy wireless
5247CAPsMAN data, for legacy wireless
5350NAT-PMP announcements, which the router sends to clients at 224.0.0.1
5351NAT-PMP server
5678MikroTik Neighbor Discovery Protocol (MNDP)
20561MAC Telnet, MAC WinBox and MAC ping (MAC server)
listen-portWireGuard: the port set on each interface
note

MAC Telnet, MAC WinBox and MAC ping work on layer 2: the packets are addressed to the router's MAC address and carry the IP addresses 0.0.0.0 and 255.255.255.255. The IP firewall does not stop them: the MAC server answers even when a filter rule drops UDP port 20561. To limit MAC access, set allowed-interface-list in /tool/mac-server.

IP protocols​

ProtocolUsed by
1ICMP
2IGMP (IGMP proxy)
4IPIP tunnels
41IPv6 encapsulation (6to4)
46RSVP for MPLS traffic engineering
47GRE: PPTP, EoIP and GRE tunnels
50ESP for IPsec
51AH for IPsec
58ICMPv6, including IPv6 Neighbor Discovery
89OSPF
103PIM (PIM-SM)
112VRRP

For all properties, see /ip/service and /ip/service/webserver in the CLI reference.