For any MikroTik gateway — not just PPPoE or Hotspot setups. Masquerade, optional port forwarding, WAN-side hardening, and basic brute-force protection, generated together.
Unlike the PPPoE and Hotspot generators, this one isn't tied to subscriber access at all — it's the baseline every internet-facing MikroTik router should have, regardless of what else runs on it.
Masquerade scoped to your actual LAN subnet, not the whole router — tighter than a blanket rule.
For beginners: scoping the rule to your LAN subnet (instead of "all traffic") means only your own devices get translated — if the router ever has a second internal network added later, it won't silently get masqueraded too.
Optional dst-nat rule for exposing one internal service (a camera, a server) without opening the whole LAN.
For beginners: only forward the specific port you actually need. Every forwarded port is a door into your LAN from the public internet — the fewer you open, the smaller your exposure.
Closes Winbox, Telnet, FTP, API, and optionally SSH to anyone on the WAN side.
For beginners: this is the single highest-impact rule on this page. See the router security guide for why these specific ports matter and what gets scanned first.
New connection attempts to router services beyond a threshold get temporarily blacklisted via address-list.
For beginners: this catches what service hardening alone doesn't — an address hammering your router with login attempts gets auto-blocked for a period, even on ports you didn't explicitly close.
Standard established/related accept plus invalid drop — same baseline as the PPPoE and Hotspot generators.
For beginners: "invalid" connections are malformed or out-of-sequence packets that don't belong to any real session — dropping them is a near-zero-risk way to filter out a lot of scanning noise.
Download the .rsc file and run /import nat-firewall-config.rsc from Winbox's terminal.
Want the reasoning behind each rule, not just the script? Read the full NAT + Firewall setup guide — covers why masquerade should be scoped to your LAN, which ports actually get scanned, and how brute-force protection works under the hood.
What the generator produces with the default values and hardening options checked — a full RouterOS NAT + firewall configuration, ready to import.
# NAT — masquerade scoped to the LAN subnet /ip firewall nat add chain=srcnat src-address=192.168.1.0/24 out-interface=ether1 action=masquerade comment="LAN masquerade" # Service hardening — WAN-side management ports closed /ip firewall filter add chain=input connection-state=established,related action=accept comment="Accept established/related" add chain=input connection-state=invalid action=drop comment="Drop invalid" add chain=input in-interface=ether1 protocol=tcp dst-port=8291,23,21,8728,8729 action=drop comment="Block Winbox/Telnet/FTP/API from WAN" # Brute-force protection add chain=input connection-state=new dst-port=8291 protocol=tcp src-address-list=blocked action=drop comment="Drop blocked brute-force attempts" add chain=input connection-state=new dst-port=8291 protocol=tcp action=add-src-to-address-list address-list=blocked address-list-timeout=1d comment="Blacklist after repeated attempts" # Forward chain — baseline add chain=forward connection-state=established,related action=accept comment="Accept established/related" add chain=forward connection-state=invalid action=drop comment="Drop invalid"
Fill in your WAN interface and LAN subnet in the generator above. It builds a masquerade rule scoped to your LAN, optional port forwarding, WAN-side service hardening (closing Winbox, Telnet, FTP, and the API), and brute-force protection, all generated together. Download it as a .rsc file and run /import nat-firewall-config.rsc. See the full setup guide for the reasoning behind each rule.
No — this page is for any MikroTik gateway, including ones not running PPPoE or Hotspot at all. If you are running PPPoE or Hotspot, the PPPoE generator and Hotspot generator already include their own baseline firewall rules, so this page is most useful for a standalone gateway or for the extra layer (port forwarding, brute-force protection) they don't cover.
At minimum: Winbox (8291), Telnet (23), FTP (21), and the API (8728/8729). None of these need to be reachable from the public internet — see the router security guide for the full reasoning.
Only if you're managing the router remotely through a port this script closes. Always test on a device you can reach physically, or keep a Winbox session open while applying firewall changes for the first time.
No. Everything runs in the browser with plain JavaScript — nothing typed into the form is transmitted to any server. See the privacy policy for details.