Firewall and QoS Case Studies
These case studies show practical firewall and QoS configurations, including brute-force prevention, DDoS protection, connection-rate rules, port knocking, and advanced firewall designs. Use them as examples for common security policies.
SSH brute-force protection
Protect an internet-facing SSH service on RouterOS with firewall rules that count new connections per source address and block a source that opens too many in a short time. Covers what to do before exposing SSH, placing the rules in the default firewall, exempting trusted addresses, IPv6, checking and unblocking, and how many password guesses the rules still allow.
Building Advanced Firewall
This page guides building an advanced firewall on MikroTik RouterOS by configuring interface lists, filtering rules for IPv4 and IPv6, accepting ICMP/DHCPv6 while blocking invalid addresses, and managing traffic flows between WAN and LAN interfaces.
Connection rate
Connection Rate is a MikroTik RouterOS firewall feature that monitors and filters traffic based on connection speed, using 'connection-bytes' and 'connection-rate' to detect high-speed connections for prioritization or throttling.
DDoS protection
Limit denial-of-service attacks with RouterOS firewall rules: count new connections per source and destination with dst-limit, put pairs that exceed the rate on address lists and drop them in the raw table. Covers how the detection works, its limits, protecting the router itself, SYN floods with TCP SYN cookies and why SYN-ACK floods are dropped as invalid.
Port knocking
Port knocking keeps the management ports of a RouterOS router closed until a client connects to a secret sequence of ports; the firewall then adds the client to a trusted address list. Covers the knock rules in the default firewall, knocking from a client, a blacklist against port scans, a passphrase knock with layer 7, and checking the lists.