MikroTik threat feeds
Load Q-Feeds threat intelligence into RouterOS with our open source scripts. Malicious IP addresses land in a firewall address-list that your filter rules drop, and the list keeps itself up to date.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and MikroTik integration?
Two RouterOS scripts do the work. A full import fetches the complete Q-Feeds malware IP list and writes it to the address-list Malware-List, and a differential update collects only the changes since your last pull. You add both as scripts on the router and let the scheduler run them.
Once the list is in place, you point your firewall filter rules at it and RouterOS drops traffic to and from those addresses. The scripts are open source, published under the MIT licence, and free to use with any Q-Feeds licence, including the free Community edition.
Two scripts, one address-list
Full import
Fetches the entire malware IP list page by page and replaces the address-list in one go. If the download fails, the previous list is restored automatically, so the router is never left unprotected. Run it daily or weekly.
Differential update
Fetches only the additions and removals since your last pull, which keeps the run short and the router idle in between. Schedule it to match your licence: once a day on Community, every four hours on Plus, every twenty minutes on Premium.
Why add Q-Feeds to your firewall
-
Enhanced threat detection
Cross-reference threat information to reduce false positives and identify genuine threats more effectively.
-
Updated every 20 minutes
Your firewall stays ahead of the latest threats with intelligence refreshed every 20 minutes.
-
Increased resilience
Rely on multiple sources for continuous protection and reduce the risk of blind spots in your security.
-
Improved incident response
Faster, more precise response right on the edge of your network, saving time on internal investigations.
Integrate Q-Feeds with MikroTik in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and copy your personal API token.
Add the scripts
Copy both scripts from GitHub into System, Scripts on the router and paste your token into each one.
Schedule them
Create a scheduler for the full import and one for the differential update, at the interval your licence allows.
Drop the traffic
Add filter rules that drop traffic to and from the Malware-List address-list, and the router blocks known bad hosts.
Prefer a different platform?
Frequently asked questions about the MikroTik integration
How do I add threat feeds to MikroTik RouterOS?
You add two Q-Feeds scripts under System, Scripts, paste your API token into both, and schedule them. They fill the firewall address-list Malware-List, which you then use in your filter rules.
Which RouterOS version do I need?
RouterOS 7.15 or later, tested up to 7.20. You also need admin rights on the router and outbound HTTPS access to api.qfeeds.com.
Does the list survive a reboot?
By default the entries are kept in RAM, which spares the flash memory of the router and disappears on reboot. The scheduler fills the list again on the next run. You can switch to persistent storage in the script if you prefer.
How often are the feeds updated?
Q-Feeds refreshes indicators every 20 minutes on Premium, every four hours on Plus and once a day on Community. You set the scheduler for the differential update to the same rhythm.
Is there a free version?
Yes. The Q-Feeds Community edition is free and lets you test the MikroTik integration before upgrading to Plus or Premium. The scripts themselves are open source under the MIT licence.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access