Services and Ports You Must Disable on MikroTik RouterOS for Maximum Security

The security of your network infrastructure is paramount, especially when dealing with devices that manage and route your network traffic. MikroTik RouterOS is a powerful tool, but like any technology, it can have its vulnerabilities if not properly configured. This guide provides an in-depth look at the services and ports you must disable on MikroTik RouterOS to enhance your network security.
In this comprehensive tutorial, we will walk you through the specific services that pose risks, the steps to disable them, and recommended configurations to ensure your MikroTik router is as secure as possible. From disabling unnecessary services to implementing strong firewall rules, you will learn how to protect your network from unauthorized access and potential attacks.
Understanding the Risks of Open Ports and Services
Every service that listens for connections on your router opens a potential door for attackers. Understanding which services are unnecessary and which ones can be exploited is the first step in hardening your MikroTik RouterOS. Hereâs a breakdown of common services that should be considered for disabling.
Common Vulnerable Services
- Telnet (Port 23)
- FTP (Port 21)
- HTTP (Port 80)
- API (Port 8728)
- Winbox (Port 8291)
- SSH (Port 22)
Step 1: Disable Telnet and FTP
Both Telnet and FTP are outdated protocols that transmit data in plain text. This means that any sensitive information, such as usernames and passwords, can be easily intercepted by attackers.
Disabling Telnet
- Access your MikroTik RouterOS via Winbox or SSH.
- Navigate to IP > Services.
- Locate the Telnet service (port 23) in the list.
- Double-click on the Telnet entry and click on Disable.
Disabling FTP
- While still in the IP > Services menu, find the FTP service (port 21).
- Double-click on the FTP entry and click on Disable.
Step 2: Switch from HTTP to HTTPS
Running a web server on port 80 can expose your router to various attacks. Instead, configure your router to use HTTPS (port 443).
Configuring HTTPS
- Go to IP > Services.
- Find the HTTP service and disable it.
- Add a new service by clicking on Add New.
- Set the service type to HTTPS and configure the appropriate port (443).
Step 3: Disable the API Services
If you are not using the MikroTik API for remote management, it is advisable to disable it.
Disabling API and API-SSL
- Return to the IP > Services menu.
- Find API (port 8728) and API-SSL (port 8729) and disable them both.
Step 4: Secure Winbox Access
Winbox is a powerful tool for managing MikroTik devices, but it can also be a target for attackers. By restricting access to trusted IP addresses, you can significantly reduce the risk.
Setting Up IP Whitelist for Winbox
- Open IP > Firewall > Address Lists.
- Create a new address list for trusted IPs.
- Go to IP > Services and find Winbox (port 8291).
- Set the allowed IP addresses in the Access section.
Step 5: Change the Default SSH Port
By changing the default SSH port (22) to a non-standard port, you can reduce the likelihood of automated attacks.
Changing the SSH Port
- Navigate to IP > Services.
- Locate the SSH service and double-click it.
- Change the port number from 22 to a custom port (e.g., 2222).
- Click OK to apply the changes.
Step 6: Disable Discovery Protocols on WAN Interfaces
Discovery protocols such as MNDP, CDP, and LLDP can reveal information about your network to potential attackers. Disabling these on WAN interfaces is crucial.
Disabling Discovery Protocols
- Go to Interfaces.
- Select the WAN interface and click on Edit.
- Disable MNDP, CDP, and LLDP.
Step 7: Disable MAC-Telnet and MAC-Winbox
These services allow connections using MAC addresses instead of IP addresses and can be a security risk if not managed properly.
Disabling MAC Services
- Return to IP > Services.
- Find MAC-Telnet and MAC-Winbox and disable both services.
Step 8: Configure Strong Firewall Rules
Implementing a strong firewall is essential to protect your router from unauthorized access.
Creating Firewall Input Chain Drop Rules
- Go to IP > Firewall.
- Select the Filter Rules tab.
- Add a new rule to drop all traffic that is not explicitly allowed.
- Position this rule at the top of the chain.
DomineTec Tech Tip: Always back up your router configuration before making changes. This will allow you to restore the previous settings if something goes wrong.
MikroTik Service Ports Overview
| Service | Port | Default Status | Vulnerability Risk | Recommended Setting |
|---|---|---|---|---|
| Telnet | 23 | Enabled | High | Disable |
| FTP | 21 | Enabled | High | Disable |
| HTTP | 80 | Enabled | Medium | Disable |
| API | 8728 | Enabled | High | Disable |
| Winbox | 8291 | Enabled | Medium | Restrict IP |
Advanced Troubleshooting Techniques
Sometimes, after making security adjustments, you might find that certain services or functionalities are not working as expected. Here are some troubleshooting steps to consider:
1. Checking Service Status
After disabling services, itâs important to confirm that they are indeed disabled. You can check the status of services by navigating to IP > Services. Ensure that the state indicates "Disabled" for the relevant services.
2. Reviewing Firewall Logs
For any connectivity issues, reviewing the firewall logs can provide valuable insights. You can access logs by going to Log under the System menu. Look for dropped packets that might indicate blocked services or IP addresses.
3. Testing Connectivity
Use tools like Ping and Traceroute to test connectivity to various network services. Ensure that your trusted IPs have access where necessary, and check if any changes in configuration have affected their connectivity.
Alternative Settings for Enhanced Security
If you want to take additional steps to secure your MikroTik RouterOS, consider implementing these alternative settings:
1. Implementing VLANs
By segmenting your network using VLANs, you can isolate sensitive devices from the rest of the network. This adds an additional layer of security by limiting access based on VLAN membership.
2. Enabling Port Knocking
Port knocking is a security measure that allows you to hide your open ports until a specific sequence of connection attempts is detected. This can add an extra layer of security for services like SSH.
3. Using VPNs for Remote Access
For remote management, consider using a VPN instead of exposing services like Winbox or SSH to the internet. This ensures that all communication is encrypted and secure.
Long-Term Care Tips for MikroTik RouterOS
Maintaining the security of your MikroTik RouterOS is an ongoing task. Here are some long-term care tips:
1. Regular Firmware Updates
Keep your router's firmware up to date to benefit from the latest security patches and features. Check for updates regularly and apply them as soon as possible.
2. Periodic Security Audits
Conduct security audits periodically to review your configurations and ensure that only necessary services are enabled. This helps to identify any potential vulnerabilities that may arise over time.
3. Educating Users
Ensure that all users who have access to the router or network are educated about security best practices. This includes using strong passwords, recognizing phishing attempts, and maintaining a secure device environment.
Conclusion
By following the steps outlined in this guide, you can significantly enhance the security of your MikroTik RouterOS. Remember that security is an ongoing process, and regularly reviewing your configurations is essential to maintain a secure environment.
Frequently Asked Questions (FAQ)
1. Why should I disable Telnet and FTP?
Both protocols transmit data in plain text, making them vulnerable to interception and attacks. Disabling them helps secure your sensitive information.
2. What is the advantage of using HTTPS over HTTP?
HTTPS encrypts data transmitted between the client and server, protecting against eavesdropping and man-in-the-middle attacks, unlike HTTP.
3. How do I know if a service is safe to disable?
If you are not actively using a service, it is generally safe to disable it. Always consult the documentation for your specific use case.
4. What are the best practices for securing my MikroTik router?
Some best practices include disabling unnecessary services, configuring strong firewall rules, using strong passwords, and keeping your firmware updated.
5. Can I revert changes if something goes wrong?
Yes, if you have backed up your configuration before making changes, you can restore the previous settings easily.
Liked it? Share!






