Try leaving "interface" value en blank. The list must be first and the rule that blocks this list at next. (1º Rule) / ip firewall filter add chain=input protocol=tcp dst-port=20-23 connection-limit=1,32 action=add-src-to-address-list address-list=blacklist_ssh address-list-timeout=1w com...
i'm using this methode to block unwanted ip trying to brute force my mikrotik via FTP / ip firewall filter add chain=input in-interface=ether1 protocol=tcp dst-port=21 src-address-list=ftp_blacklist action=drop # accept 10 incorrect logins per minute / ip firewall filter add chain=output action=acce...