Hi, I think it will help you (sorry google :wink: ): /ip firewall filter add action=jump chain=input connection-state=new jump-target=detect-ddos add action=return chain=detect-ddos dst-limit=32,32,src-and-dst-addresses/10s add action=add-dst-to-address-list address-list=ddosed address-list-timeout=...