MikroTik
Our platform has been certified as a Made for Mikrotik software platform. It guarantees official recognition and full compatibility on any Router model and OS version. Mikrotik RouterOS is one of the most used Routers today by our Customers and Partners all over the world.
Overview
This guide explains how to configure our DNS filter directly on MikroTik RouterOS devices. You can choose to apply the complete configuration instantly using our automated script via the terminal, or you can configure every parameter manually step-by-step using the Winbox graphical interface.
Automated Configuration Script
If you want to configure your routerboard automatically, open a New Terminal window in your MikroTik and paste the script below. This code will automatically create the update script, schedule it to run every minute, disable peer DNS, apply our cloud servers, and create the necessary NAT redirection rules.
Before pressing enter, carefully replace USER and PASS in the script with the specific username and password assigned to your dynamic network.
# Script DNS Filter
# Create the Script
/system script
add name=FilterScript policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive source="\
\n:tool fetch url=\"https://ddns.fsflt.com/nic/update\?username=USER&password=PASS\""
# Schedule the Script to run every 1 minute
/system scheduler
add interval=60s name=FilterScheduler on-event="/system script run FilterScript" \
policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive \
start-time=startup
# Disable the use of Peer DNS
/ip dhcp-client
set use-peer-dns=no 0
# Set Cache Max TTL to 1 minute
/ip dns
set cache-max-ttl=1m
# Set the Content Filter DNS
/ip dns
set servers=185.236.104.104,185.236.105.105
# Create NAT rules
/ip firewall nat
add action=dst-nat chain=dstnat dst-port=53 protocol=udp \
to-addresses=185.236.104.104 to-ports=53
add action=dst-nat chain=dstnat dst-port=53 protocol=tcp \
to-addresses=185.236.104.104 to-ports=53If your password contains special characters like $ or ", you must insert the \ symbol before each of those characters in the code. For example, if you have the password password123$$, you have to change it to password123$$. This is strictly necessary, otherwise the MikroTik system will misinterpret those characters and the script will fail.
Manual Configuration via Winbox
If you prefer the graphical interface, log into your routerboard using Winbox and follow these manual steps.
Create the Update Script
First, you need to create a script to automatically update your dynamic IP address.
- Go to the System menu and click on Scripts.
- Click on the + symbol under the Scripts button.
- Configure the fields as follows:
- Name: Insert a recognizable name like PlatformScript.
- Policy: Leave the default policy selected.
- Source: Copy and paste the following instruction into the text area:
:tool fetch url="https://ddns.fsflt.com/nic/update\?username=USER&password=PASS"You must replace the credentials within the source code:
- USER: The dedicated username of your dynamic network.
- PASS: The specific password of your dynamic network.
Ensure you follow the special character escape rule mentioned in the warning box above if your network password contains symbols. Click OK to save the changes.
Schedule the Script
After creating the script, you must set a scheduler so it runs automatically.
- Go to the System menu and click on Scheduler.
- Click on the + symbol under the Scheduler button.
- Configure the scheduling fields:
- Name: Insert a name like PlatformScheduler.
- Interval: Choose an interval to run the script. The time format must be hh:mm:ss, meaning you should enter 00:01:00 for a one-minute interval.
- On Event: Insert the exact name of the script you created in the previous step.
Click OK to apply the changes.
Set the Cloud Filter DNS
You now need to configure the DNS routing on your MikroTik and set the MikroTik IP on your internal devices as the only DNS. To do this:
- Go to the IP menu and click on DNS.
- In the Servers field, add 185.236.104.104 and 185.236.105.105.
- Click on the OK button to save.
If you see a private IP in the Dynamic DNS field of your DNS Settings, your MikroTik is taking DNS addresses in DHCP from another device like the main modem. To avoid this, open the IP menu and click on DHCP Client. Double click on your DHCP configuration to open the properties and uncheck the Use Peer DNS entry. Click OK to apply the changes.
Optional: Redirecting DNS to Our Servers
You can create firewall rules to transparently redirect all DNS traffic to our servers. By doing this, you do not need to change DNS settings on internal devices or activate the DHCP Server.
- Open the IP menu and click on the Firewall button.
- Navigate to the NAT tab and click the Add new button to create a rule.
- Configure the fields exactly in this way:
- Enabled: Check the box.
- Chain: Select dstnat.
- Protocol: Choose udp.
- Dst. Port: Type 53.
- In. Interface: Choose your internal interface, which is bridge1 by default.
- Action: Select dst-nat.
- To Address: Insert 185.236.104.104.
- To Port: Type the port number chosen before, which defaults to 53.
Click OK to apply the new configuration. Finally, create another rule strictly equal to the previous one, but change the Protocol field to tcp instead of udp.
Related Guides
Explore these topics for advanced configurations and troubleshooting:
Configuration Guide | Description & Focus |
|---|---|
Instructions for securing your DNS queries using the DNS over HTTPS protocol. | |
Steps to prevent external abuse and secure your network perimeter. | |
Advanced setup for environments with multiple internet connections. | |
Troubleshooting steps for dynamic IP update failures. | |
A guide to managing multiple distinct filtering profiles on a single device. |