MikroTik integration

MikroTik threat feeds

Load Q-Feeds threat intelligence into RouterOS with our open source scripts. Malicious IP addresses land in a firewall address-list that your filter rules drop, and the list keeps itself up to date.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and MikroTik integration?

Two RouterOS scripts do the work. A full import fetches the complete Q-Feeds malware IP list and writes it to the address-list Malware-List, and a differential update collects only the changes since your last pull. You add both as scripts on the router and let the scheduler run them.

Once the list is in place, you point your firewall filter rules at it and RouterOS drops traffic to and from those addresses. The scripts are open source, published under the MIT licence, and free to use with any Q-Feeds licence, including the free Community edition.

How it runs

Two scripts, one address-list

Full import

Fetches the entire malware IP list page by page and replaces the address-list in one go. If the download fails, the previous list is restored automatically, so the router is never left unprotected. Run it daily or weekly.

Differential update

Fetches only the additions and removals since your last pull, which keeps the run short and the router idle in between. Schedule it to match your licence: once a day on Community, every four hours on Plus, every twenty minutes on Premium.

Benefits

Why add Q-Feeds to your firewall

  • Enhanced threat detection

    Cross-reference threat information to reduce false positives and identify genuine threats more effectively.

  • Updated every 20 minutes

    Your firewall stays ahead of the latest threats with intelligence refreshed every 20 minutes.

  • Increased resilience

    Rely on multiple sources for continuous protection and reduce the risk of blind spots in your security.

  • Improved incident response

    Faster, more precise response right on the edge of your network, saving time on internal investigations.

Setup

Integrate Q-Feeds with MikroTik in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal API token.

  2. Add the scripts

    Copy both scripts from GitHub into System, Scripts on the router and paste your token into each one.

  3. Schedule them

    Create a scheduler for the full import and one for the differential update, at the interval your licence allows.

  4. Drop the traffic

    Add filter rules that drop traffic to and from the Malware-List address-list, and the router blocks known bad hosts.

FAQ

Frequently asked questions about the MikroTik integration

How do I add threat feeds to MikroTik RouterOS?

You add two Q-Feeds scripts under System, Scripts, paste your API token into both, and schedule them. They fill the firewall address-list Malware-List, which you then use in your filter rules.

Which RouterOS version do I need?

RouterOS 7.15 or later, tested up to 7.20. You also need admin rights on the router and outbound HTTPS access to api.qfeeds.com.

Does the list survive a reboot?

By default the entries are kept in RAM, which spares the flash memory of the router and disappears on reboot. The scheduler fills the list again on the next run. You can switch to persistent storage in the script if you prefer.

How often are the feeds updated?

Q-Feeds refreshes indicators every 20 minutes on Premium, every four hours on Plus and once a day on Community. You set the scheduler for the differential update to the same rhythm.

Is there a free version?

Yes. The Q-Feeds Community edition is free and lets you test the MikroTik integration before upgrading to Plus or Premium. The scripts themselves are open source under the MIT licence.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access