Use this baseline to allow LAN Internet access while limiting SSH and WinBox to one administrator address. It includes IPv4 and IPv6 rules. On an existing router, edit the matching rules in their current order; the complete blocks below are for empty chains.
Allow LAN Internet and one administrator
This policy assumes an existing br-lan at 10.42.50.1/24, an administrator at 10.42.50.10, and a DHCP WAN on ether1. LAN DHCP and DNS already run on the router; the basic Internet setup creates those services. The filter examples below are for empty chains. On a configured router, first read /ip/firewall/filter/print detail and edit its existing rule order.
Check /interface/list/print and /interface/list/member/print. If WAN/LAN are missing, create them and add the routed uplink and LAN bridge:
/interface/list
add name=WAN
add name=LAN
/interface/list/member
add list=WAN interface=ether1
add list=LAN interface=br-lanDo not add duplicate lists or members. Use Safe Mode (Ctrl+X) through console or an independent management path before changing the firewall; a wrong source address or rule position can end your session.
/ip/firewall/filter
add chain=input action=accept connection-state=established,related comment="Return traffic to router"
add chain=input action=drop connection-state=invalid comment="Reject invalid state"
add chain=input action=accept in-interface-list=WAN protocol=udp src-port=67 dst-port=68 comment="WAN DHCP reply"
add chain=input action=accept in-interface-list=LAN protocol=udp dst-port=67 comment="LAN DHCP requests"
add chain=input action=accept in-interface-list=LAN protocol=udp dst-port=53 comment="LAN DNS UDP"
add chain=input action=accept in-interface-list=LAN protocol=tcp dst-port=53 comment="LAN DNS TCP"
add chain=input action=accept in-interface-list=LAN src-address=10.42.50.10 protocol=tcp dst-port=22,8291 comment="Admin workstation only"
add chain=input action=accept protocol=icmp comment="IPv4 diagnostics and errors"
add chain=input action=drop comment="Deny other router input"
add chain=forward action=accept connection-state=established,related comment="Return traffic through router"
add chain=forward action=drop connection-state=invalid comment="Reject invalid forwarding"
add chain=forward action=accept in-interface-list=LAN out-interface-list=WAN comment="LAN Internet access"
add chain=forward action=drop comment="Deny other forwarding"The input rules allow services on the router; forward allows LAN traffic through it. Keep the final drops after the specific permits.
IPv6 needs its own policy
Globally addressed IPv6 clients can be reachable without any port-forward mapping. Apply explicit input and forward protection before enabling IPv6 service. The example keeps management on the allowed IPv4 path, permits ICMPv6 for discovery and path-MTU operation, allows direct-link DHCPv6 client replies, and permits LAN Internet traffic.
/ipv6/firewall/filter
add chain=input action=accept connection-state=established,related
add chain=input action=drop connection-state=invalid
add chain=input action=accept protocol=icmpv6 comment="Neighbor discovery and IPv6 errors"
add chain=input action=accept in-interface-list=WAN src-address=fe80::/10 protocol=udp src-port=547 dst-port=546 comment="Direct-link DHCPv6 replies"
add chain=input action=drop comment="IPv6 management uses no implicit LAN trust"
add chain=forward action=accept connection-state=established,related
add chain=forward action=drop connection-state=invalid
add chain=forward action=accept protocol=icmpv6 comment="Allow IPv6 diagnostics and PMTU"
add chain=forward action=accept in-interface-list=LAN out-interface-list=WAN
add chain=forward action=dropThis deliberately allows ICMPv6, including diagnostics. More restrictive deployments should select required ICMPv6 types using RFC 4890, not block it wholesale. This baseline supplies LAN DNS and DHCP over IPv4. The optional rules below permit existing IPv6 DNS and DHCPv6 services; they do not enable those services. For DNS on br-lan, replace documentation client prefix 2001:db8:42:50::/64 with the real prefix and identify the IPv6 input drop with /ipv6/firewall/filter/print detail where chain=input.
/ipv6/firewall/filter
add chain=input action=accept in-interface=br-lan src-address=2001:db8:42:50::/64 protocol=udp dst-port=53 place-before=<IPv6-input-drop-id>
add chain=input action=accept in-interface=br-lan src-address=2001:db8:42:50::/64 protocol=tcp dst-port=53 place-before=<IPv6-input-drop-id>For a local DHCPv6 server, use /ipv6/firewall/filter/add chain=input action=accept in-interface=br-lan src-address=fe80::/10 protocol=udp src-port=546 dst-port=547 place-before=<IPv6-input-drop-id>. This admits directly attached clients; DHCPv6 relay traffic needs a rule for the actual relay source and server ports.
Address lists, ordering and FastTrack
/ip/firewall/address-list/add list=admin-v4 address=10.42.50.10 comment="Wired administrator"To use this list in the administrator permit from the baseline, first run /ip/firewall/filter/print detail where chain=input and identify the rule with comment "Admin workstation only". Replace its old source match with the list; substitute the verified rule number. Leaving the old 10.42.50.10 match in place would also restrict any later addresses added to the list.
/ip/firewall/filter/set <admin-rule-id> src-address=0.0.0.0/0 src-address-list=admin-v4If queues or policy routing stop working after enabling FastTrack, exclude those connections before the FastTrack rule.
Prove the policy
Test a new allowed management session, a blocked session from another LAN address, LAN-to-WAN traffic and an external inbound attempt. Read filter counters before and after each test. Repeat for IPv6 where provisioned. Check that an earlier broad accept or established connection is not making a new rule appear to work.
/ip/firewall/filter/print stats
/ipv6/firewall/filter/print stats