Hello, I am using mikrotik for DDoS mitigation networks, there is only one big drawback, apparently mikrotik is not layers to filter a HEX address, as well as problems with the directories / ip firewall addres-list since they are not updated at least Not in real time, in conclusion it is necessary to filter HEX content without using layer 7 for the computational cost involved and is ineffective when it comes to 3 or 4 million packets per second … enlighten me with your wisdom