Thank you, didn't know RB4011 has some problems with SFP+ and WiFi.
So will wait some weeks and will see if I will change CCR for something other.
/ip firewall filter add action=drop chain=input comment="drop attackers ip pools (vpn)" src-address-list=block_attackers
I already deleted rules because don't work. Maybe synology has option to do that but I want to use limit it via mikrotik.Please show your configuration.
It works because no device can access to facebook after applying that rules. So it works but I need to allow that sites for 1 IP.as far as my knowledge goes, social sites, i.e. facebook is encrypted (https) and router can't see inside the packets