I’ve done my research. I created several lists of the most notorious scanners doing open port scanning. Love these guys, or hate them… Best to just block input on these guys.
Put this into your terminal, then if its easier, move the firewalls up your chains. Inputs near the top, forwards near the middle.. test as needed.
Feel free to give me comments:
## SHODAN Block List for Mikrotik
/ip firewall address-list
add address=198.20.69.74/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=198.20.69.98/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=198.20.99.130/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=93.120.27.62/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=66.240.236.119/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=71.6.135.131/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=66.240.192.138/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=71.6.167.142/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=82.221.105.6/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=82.221.105.7/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=71.6.165.200/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=188.138.9.50/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=85.25.103.50/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=85.25.43.94/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=71.6.146.185/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=71.6.158.166/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=198.20.87.98/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=209.126.110.38/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=66.240.219.146/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=104.236.198.48/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=104.131.0.69/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=162.159.244.38/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=184.105.247.196/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=141.212.122.112/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=125.237.220.106/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=192.81.128.37/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=74.82.47.2/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=216.218.206.66/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=184.105.139.67/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=54.81.158.232/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=141.212.122.144/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=141.212.122.128/32 comment="SHODAN_Block_List" list=SHODANBlocks
add address=54.206.70.29/32 comment="SHODAN_Block_List" list=SHODANBlocks
## Censys Block List for Mikrotik
/ip firewall address-list
add address=66.132.159.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=162.142.125.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=167.94.138.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=167.94.145.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=167.94.146.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=167.248.133.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=199.45.154.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=199.45.155.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=206.168.34.0/24 comment="Censys_Block_List" list=CensysBlocks
add address=206.168.35.0/24 comment="Censys_Block_List" list=CensysBlocks
## ShadowServer Block List for Mikrotik
/ip firewall address-list
add address=184.105.139.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=216.218.206.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=74.82.47.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=184.105.247.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=65.49.20.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=65.49.1.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=64.62.156.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=184.105.247.0/24 comment="Shadow_Block_List" list=ShadowBlocks
add address=64.62.197.0/24 comment="Shadow_Block_List" list=ShadowBlocks
## Add the Rules for input drop
/ip firewall filter
add action=drop chain=input comment="Drop all traffic to-from addresses on SHODAN Block address list" src-address-list=SHODANBlocks
add action=drop chain=input comment="Drop all traffic to-from addresses on Censys Block address list" src-address-list=CensysBlocks
add action=drop chain=input comment="Drop all traffic to-from addresses on Shadow Block address list" src-address-list=ShadowBlocks
## Add the Rules for foward drop
/ip firewall filter
add action=drop chain=forward comment="Drop all traffic to-from addresses on SHODAN Block address list" dst-address-list=SHODANBlocks
add action=drop chain=forward comment="Drop all traffic to-from addresses on Censys Block address list" dst-address-list=CensysBlocks
add action=drop chain=forward comment="Drop all traffic to-from addresses on Shadow Block address list" dst-address-list=ShadowBlocks