How to block DNS resolution from outside in Mikrotik
3 min
Overview
It is very important to block the DNS service on port 53 for incoming connections on your Router or Firewall. Doing this increases your network security and helps avoid cyber attacks such as DDOS.
Configuration Steps
To secure your network, connect to your MikroTik using Winbox and open a New Terminal. Copy and paste the following commands into the console:
/ip firewall filter
add chain=input in-interface=IN-INT protocol=udp dst-port=53 action=drop
add chain=input in-interface=IN-INT protocol=tcp dst-port=53 action=drop
/ip firewall filter
add chain=forward in-interface=IN-INT protocol=udp dst-port=53 action=drop
add chain=forward in-interface=IN-INT protocol=tcp dst-port=53 action=dropBefore executing the commands, you must replace IN-INT in the code above with the actual name of your MikroTik WAN interface.
If you use multiple WAN interfaces on your MikroTik, you must re-run the commands above multiple times, replacing IN-INT with the names of all your other WAN interfaces to ensure complete protection.