
How to Blacklist Filters on MikroTik RouterOS?
To prevent your users from accessing blacklist IP addresses, you need to create the following firewall rules. Thus, we protect our users from unnecessary sites.
In order to use any of the following lists you will want to add a rule to your input or forward chains like the following:
/ip firewall filter add action=drop chain=input
comment=" Drop new connectionsfrom blacklisted IP's to this router"
connection-state=new in-interface=ether1 src-address-list=blacklist
or
/ip firewall filter
add action=drop chain=forward comment=" Drop new connectionsfrom blacklisted
IP's to this router" dst-address-list=blacklist
SpamHaus
“Spamhaus Don’t Route Or Peer List (DROP)”
The DROP list will not include any IP address space under the control of any legitimate network – even if being used by “the spammers from hell”. DROP will only include netblocks allocated directly by an established Regional Internet Registry (RIR) or National Internet Registry (NIR) such as ARIN, RIPE, AFRINIC, APNIC, LACNIC or KRNIC or direct RIR allocations.”
