How to configure DNS filtering on Mikrotik devices
Overview
Access your MikroTik via the WinBox application or the Web interface. You can connect to the control panel using SSH, Web, or WinBox. Please note that in this guide we have used WinBox to configure the device, which is recommended.
Create the Script
First, you need to create a new Script to synchronize your IP. Proceed as follows:
- Go to the System menu and then click on Scripts.
- In the window that opens, click on the + symbol under Scripts.
- Choose a name to give the Script, for example PlatformScript.
- Leave the default policies active.
- In the Source field, paste the following instruction:
:tool fetch url= urlYou must replace the words USER and PASS as follows:
- USER: The dedicated username of your dynamic network.
- PASS: The specific password of your dynamic network.
If your password contains special characters such as $ or ", you must enter the \ symbol before each of these characters. For example, suppose you have the password password123$$, this must be written exactly as password123$$. This change is strictly necessary otherwise the MikroTik system would see those symbols as commands and not as simple characters.
Click OK to save the changes.
Schedule the Script
At this point, it is necessary to create a Scheduler so that it automatically executes the Script created earlier. Proceed as follows:
- Go to the System menu and click on Scheduler.
- In the window that opens, click on the + symbol under the Scheduler heading.
- Choose a name to give the Scheduler, for example PlatformScheduler.
- Choose the script execution time interval, for example 5 minutes. The format must be hh:mm:ss, so in our case it will be 00:05:00.
- In the On Event field, enter the exact name of the previously created Script. In our example, it will be PlatformScript.
Click OK to save.
DNS Cloud Filter Configuration
Set the following DNS addresses, either using a DHCP Server or manually, on the various devices inside your network:
- Primary DNS: 185.236.104.104
- Secondary DNS: 185.236.105.105
Alternatively, it is possible to change the DNS used by the MikroTik so that the router IP itself is used as the only DNS on the internal network devices. To do this, proceed as follows:
- Go to the IP menu and click on DNS.
- In the window that opens, enter the following IPs in the Servers field respectively:
- 185.236.104.104
- 185.236.105.105
- Click on the OK button to save.
If there is an address within the Dynamic DNS field on your DNS Settings, it means that the MikroTik also takes DNS addresses from the DHCP of another device on the network like your main modem. To avoid this, open the IP menu and click on DHCP Client. Double-click on the entry for the active DHCP client to open the respective properties, remove the check mark from the Use Peer DNS item, and click OK to save.
Optional: Deny DNS Changes by Users
You can create some Firewall rules with the purpose of automatically redirecting all DNS traffic on port 53 to our Servers. This way you will not need to change the DNS settings on the individual devices inside the network.
To do this, open the IP menu and click on the Firewall button. Then click on the NAT tab and click on the Add new button to create a new rule.
Fill in the various fields as follows:
- Enabled: Check the box to enable the rule.
- Chain: Select dstnat from the drop-down menu.
- Protocol: Choose udp.
- Dst. Port: Enter 53.
- In. Interface: Choose the internal network interface to be filtered. By default it is called bridge1.
- Action: Select dst-nat.
- To Address: Enter the address 185.236.104.104.
- To Port: Enter the port number chosen previously, which defaults to 53. If a port other than 53 was registered on your Cloud panel, enter that specific port instead.
Click OK to save.
Finally, create another rule exactly the same as the previous one, except the Protocol field must be tcp instead of udp.
Related Articles
Configuration Guide | Description & Focus |
|---|---|
Advanced setup for environments with multiple internet connections. | |
A guide to managing multiple distinct filtering profiles on a single device. |