/ip firewall  →  RouterOS config generator

Generate a tested baseline NAT + Firewall config
in seconds

For any MikroTik gateway — not just PPPoE or Hotspot setups. Masquerade, optional port forwarding, WAN-side hardening, and basic brute-force protection, generated together.

Free, no signup Runs 100% in your browser Nothing you type is sent anywhere Tested on RouterOS v7.x

Presets only fill editable examples. Confirm your real WAN interface, LAN subnet, and remote-management needs before exporting.

Interfaces & LAN

The masquerade rule is scoped to this subnet — only traffic actually originating here gets translated out the WAN interface.

Port forwarding (optional)
Hardening
nat-firewall-config.rsc
  1. Export a backup before importing anything.
  2. Review the generated interfaces, IP ranges, and RADIUS values against your topology.
  3. Test on one reachable router first, then verify login, accounting, NAT, and management access.

What this script sets up

Unlike the PPPoE and Hotspot generators, this one isn't tied to subscriber access at all — it's the baseline every internet-facing MikroTik router should have, regardless of what else runs on it.

01 · NAT

Masquerade scoped to your actual LAN subnet, not the whole router — tighter than a blanket rule.

For beginners: scoping the rule to your LAN subnet (instead of "all traffic") means only your own devices get translated — if the router ever has a second internal network added later, it won't silently get masqueraded too.

02 · Port forward

Optional dst-nat rule for exposing one internal service (a camera, a server) without opening the whole LAN.

For beginners: only forward the specific port you actually need. Every forwarded port is a door into your LAN from the public internet — the fewer you open, the smaller your exposure.

03 · Service hardening

Closes Winbox, Telnet, FTP, API, and optionally SSH to anyone on the WAN side.

For beginners: this is the single highest-impact rule on this page. See the router security guide for why these specific ports matter and what gets scanned first.

04 · Brute-force protection

New connection attempts to router services beyond a threshold get temporarily blacklisted via address-list.

For beginners: this catches what service hardening alone doesn't — an address hammering your router with login attempts gets auto-blocked for a period, even on ports you didn't explicitly close.

05 · Forward chain

Standard established/related accept plus invalid drop — same baseline as the PPPoE and Hotspot generators.

For beginners: "invalid" connections are malformed or out-of-sequence packets that don't belong to any real session — dropping them is a near-zero-risk way to filter out a lot of scanning noise.

Import

Download the .rsc file and run /import nat-firewall-config.rsc from Winbox's terminal.

Before you deploy: if you manage this router remotely, keep a Winbox/console session open while testing — a misordered firewall rule can lock you out of your own router. Test on a device you can reach physically before relying on this in production.

Want the reasoning behind each rule, not just the script? Read the full NAT + Firewall setup guide — covers why masquerade should be scoped to your LAN, which ports actually get scanned, and how brute-force protection works under the hood.

Example output

What the generator produces with the default values and hardening options checked — a full RouterOS NAT + firewall configuration, ready to import.

nat-firewall-config.rsc — example
# NAT — masquerade scoped to the LAN subnet
/ip firewall nat
add chain=srcnat src-address=192.168.1.0/24 out-interface=ether1 action=masquerade comment="LAN masquerade"

# Service hardening — WAN-side management ports closed
/ip firewall filter
add chain=input connection-state=established,related action=accept comment="Accept established/related"
add chain=input connection-state=invalid action=drop comment="Drop invalid"
add chain=input in-interface=ether1 protocol=tcp dst-port=8291,23,21,8728,8729 action=drop comment="Block Winbox/Telnet/FTP/API from WAN"

# Brute-force protection
add chain=input connection-state=new dst-port=8291 protocol=tcp src-address-list=blocked action=drop comment="Drop blocked brute-force attempts"
add chain=input connection-state=new dst-port=8291 protocol=tcp action=add-src-to-address-list address-list=blocked address-list-timeout=1d comment="Blacklist after repeated attempts"

# Forward chain — baseline
add chain=forward connection-state=established,related action=accept comment="Accept established/related"
add chain=forward connection-state=invalid action=drop comment="Drop invalid"

Frequently asked questions

How do I configure NAT and a firewall on MikroTik?

Fill in your WAN interface and LAN subnet in the generator above. It builds a masquerade rule scoped to your LAN, optional port forwarding, WAN-side service hardening (closing Winbox, Telnet, FTP, and the API), and brute-force protection, all generated together. Download it as a .rsc file and run /import nat-firewall-config.rsc. See the full setup guide for the reasoning behind each rule.

Is this generator only for WISP/PPPoE routers?

No — this page is for any MikroTik gateway, including ones not running PPPoE or Hotspot at all. If you are running PPPoE or Hotspot, the PPPoE generator and Hotspot generator already include their own baseline firewall rules, so this page is most useful for a standalone gateway or for the extra layer (port forwarding, brute-force protection) they don't cover.

Which ports should be closed on the WAN interface?

At minimum: Winbox (8291), Telnet (23), FTP (21), and the API (8728/8729). None of these need to be reachable from the public internet — see the router security guide for the full reasoning.

Will this lock me out of my own router?

Only if you're managing the router remotely through a port this script closes. Always test on a device you can reach physically, or keep a Winbox session open while applying firewall changes for the first time.

Does this tool send my router's configuration anywhere?

No. Everything runs in the browser with plain JavaScript — nothing typed into the form is transmitted to any server. See the privacy policy for details.