Tady to bude těžké, hodně jsem s tím experimentoval, metoda pokus omyl:
[doma@MikroTik-doma] /ip firewall filter> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; Sitove porty pouzivane sluzbou Xbox Live
;;; http://support.xbox.com/cs-CZ/xbox-360/networking/network-ports-used-xbox-live
chain=input action=accept protocol=tcp dst-port=3074 log=no log-prefix=""
1 chain=input action=accept protocol=udp dst-port=3074 log=no log-prefix=""
2 X chain=input action=accept protocol=udp dst-port=88 log-prefix=""
3 X chain=input action=accept protocol=tcp dst-port=53 log-prefix=""
4 X chain=input action=accept protocol=udp dst-port=53 log-prefix=""
5 ;;; SSTP
chain=input action=accept protocol=tcp dst-port=443 log-prefix=""
6 ;;; L2TP
chain=input action=accept protocol=udp dst-port=1701,500,4500 log-prefix=""
7 ;;; L2TP
chain=input action=accept protocol=ipsec-esp log-prefix=""
8 ;;; PPTP
chain=input action=accept protocol=tcp dst-port=1723 log-prefix=""
9 ;;; PPTP - GRE
chain=input action=accept protocol=tcp dst-port=47 log-prefix=""
10 ;;; Povoleni administrace pomoci prohlizece (nesifrovane)
chain=input action=accept protocol=tcp dst-port=80 log-prefix=""
11 ;;; Obrana pred utokem ssh brute forcers (umozni prihlasit se 3x do minuty, pak BAN na 30 dni)
;;; Zdroj: http://wiki.mikrotik.com/wiki/Bruteforce_login_prevention_%28FTP_%26_SSH
chain=input action=drop protocol=tcp src-address-list=ssh_blacklist dst-port=22 log-prefix=""
12 chain=input action=add-src-to-address-list connection-state=new protocol=tcp src-address-list=ssh_stage3 address-list=ssh_blacklist address-list-timeout=4w2d dst-port=22 log-prefix=""
13 chain=input action=add-src-to-address-list connection-state=new protocol=tcp src-address-list=ssh_stage2 address-list=ssh_stage3 address-list-timeout=1m dst-port=22 log-prefix=""
14 chain=input action=add-src-to-address-list connection-state=new protocol=tcp src-address-list=ssh_stage1 address-list=ssh_stage2 address-list-timeout=1m dst-port=22 log-prefix=""
15 chain=input action=add-src-to-address-list connection-state=new protocol=tcp address-list=ssh_stage1 address-list-timeout=1m dst-port=22 log-prefix=""
16 ;;; povolen SSH z internetu
chain=input action=accept protocol=tcp dst-port=22 log-prefix=""
17 ;;; default configuration
chain=input action=accept protocol=icmp log-prefix=""
18 ;;; default configuration
chain=input action=accept connection-state=established log-prefix=""
19 ;;; default configuration
chain=input action=accept connection-state=related log-prefix=""
20 ;;; default configuration
chain=input action=drop in-interface=ether1-gateway log-prefix=""
21 ;;; default configuration
chain=forward action=accept connection-state=established log-prefix=""
22 ;;; default configuration
chain=forward action=accept connection-state=related log-prefix=""
23 ;;; default configuration
chain=forward action=drop connection-state=invalid log-prefix=""