Home / tikoci / routeros-skills · routeros-firewall/SKILL.md · GitHub

routeros-firewall skillA

routeros-firewall is agent-read markdown (skill) from tikoci/routeros-skills: RouterOS firewall filter, NAT, mangle, and address-list configuration. Use when: writing firewall rules in RouterOS, configuring NAT, setting up address-lists or interface-lists, writing idempotent firewall scripts, configuring DNS redirect or port forwarding, or when the user mentions /ip/firewall, chain=forward, chain=input, connection-state, address-list, interface-list, or layer7-protocol on MikroTik..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# RouterOS Firewall

## Rule Ordering — Sequential, Not Priority-Based

Rules are evaluated **top-to-bottom** — first match wins. This is the biggest source of iptables confusion.

- `place-before=0` inserts at the top; default `add` appends at the bottom
- An `action=accept` rule must appear BEFORE any `action=drop` for the same traffic
- **Non-terminal actions do NOT stop evaluation:** `action=add-src-to-address-list`, `action=add-dst-to-address-list`, `action=log`, and any rule with `passthrough=yes` continue to the next rule. A `drop` rule below an `add-src-to-address-list` will still fire.

```routeros
# WRONG — drop fires before accept can match
/ip/firewall/filter/add chain=input action=drop
/ip/firewall/filter/add chain=input src-address=10.0.0.1 action=accept

# CORRECT — accept first, drop catches the rest
/ip/firewall/filter/add chain=input src-address=10.0.0.1 action=accept place-before=0
/ip/firewall/filter/add chain=input action=drop
```

## Address-Lists as Dynamic Selectors

LLMs rarely suggest this pattern — they write one rule per IP address instead. Address-lists scale to hundreds of IPs with a single firewall rule.

```routeros
…

Read the whole file at its exact version.

How to install

Latest version
mdr add tikoci/routeros-skills/routeros-firewall@git:20260626.5284858
Exact content
mdr add tikoci/routeros-skills/routeros-firewall@sha256:4ada00c81fa09c6f

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_tyld77pidydhr2wr.svg)](https://markdownregistry.com/a/art_tyld77pidydhr2wr)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260626.5284858 latest2026-06-26 5284858 7,484 BA view · diff
git:20260507.2ea4c622026-05-07 2ea4c62 7,476 BA view · diff
git:20260507.51a982c2026-05-07 51a982c 7,434 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (7484 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

tikoci/routeros-skills · 64 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_tyld77pidydhr2wr
GET https://markdownregistry.com/api/v1/resolve?ref=tikoci/routeros-skills/routeros-firewall
GET https://markdownregistry.com/api/v1/blob/4ada00c81fa09c6f9a86c52f062e5107a10c8e858685b17354afd637c2b9d646

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from tikoci/routeros-skills

routeros-app-yaml skill
tikoci/routeros-skills · routeros-app-yaml/SKILL.md · RouterOS /app YAML format for container applications (7.21+ builtin app, 7.22+ custom YAML creation). Use when: writing…
git:20260626.5284858 · audit A · 64 stars
routeros-centrs skill
tikoci/routeros-skills · routeros-centrs/SKILL.md · Use whenever a task touches a real MikroTik RouterOS device or CHR: reading or changing config, running a RouterOS CLI…
git:20260921.bf6c644 · audit A · 64 stars
routeros-command-tree skill
tikoci/routeros-skills · routeros-command-tree/SKILL.md · RouterOS command tree introspection via /console/inspect API. Use when: building tools that parse RouterOS commands…
git:20260718.14fcd40 · audit A · 64 stars
routeros-container skill
tikoci/routeros-skills · routeros-container/SKILL.md · RouterOS /container subsystem for running OCI containers on MikroTik devices. Use when: enabling containers on…
git:20260626.5284858 · audit B · 64 stars
routeros-fundamentals skill
tikoci/routeros-skills · routeros-fundamentals/SKILL.md · RouterOS v7 domain knowledge for AI agents. Use when: working with MikroTik RouterOS, writing RouterOS CLI/script…
git:20260626.5284858 · audit A · 64 stars
routeros-hotspot skill
tikoci/routeros-skills · routeros-hotspot/SKILL.md · RouterOS hotspot captive portal for wired/wireless access control. Use when: configuring hotspot on RouterOS, setting…
git:20260626.5284858 · audit B · 64 stars
routeros-mac-telnet skill
tikoci/routeros-skills · routeros-mac-telnet/SKILL.md · MAC-Telnet protocol (MikroTik Layer-2 terminal/exec over UDP 20561) wire format, session handshake, and MD5 + MTWEI…
git:20260626.c5a9200 · audit A · 64 stars
routeros-mndp skill
tikoci/routeros-skills · routeros-mndp/SKILL.md · MNDP (MikroTik Neighbor Discovery Protocol) wire format, behavior, and RouterOS /ip/neighbor integration. Use when…
git:20260626.5284858 · audit A · 64 stars
routeros-netinstall skill
tikoci/routeros-skills · routeros-netinstall/SKILL.md · MikroTik netinstall-cli for automated RouterOS device flashing. Use when: automating netinstall, writing scripts that…
git:20260417.77838ab · audit A · 64 stars
routeros-qemu-chr skill
tikoci/routeros-skills · routeros-qemu-chr/SKILL.md · MikroTik RouterOS CHR (Cloud Hosted Router) with QEMU. Use when: running RouterOS in QEMU, booting CHR images…
git:20260626.83bbe1f · audit B · 64 stars
routeros-quickchr-cli skill
tikoci/routeros-skills · routeros-quickchr-cli/SKILL.md · Answer a RouterOS question by asking RouterOS. quickchr boots a real, disposable MikroTik CHR router on the local…
git:20260921.bf6c644 · audit B · 64 stars
routeros-quickchr skill
tikoci/routeros-skills · routeros-quickchr/SKILL.md · Ground RouterOS config/scripts/API code against a REAL router using quickchr (@tikoci/quickchr) — a CLI + Bun/TS…
git:20260921.bf6c644 · audit A · 64 stars

Every file in tikoci/routeros-skills

Browse by kind, by grade A, or by owner.