https://wiki.mikrotik.com/wiki/Manual:I ... all/Filter
MikroTik RouterOS has very powerful firewall implementation with features including:
stateful packet inspection
Layer-7 protocol detection
peer-to-peer protocols filtering
traffic classification by:
source MAC address
IP addresses (network or list) and address types (broadcast, local, multicast, unicast)
port or port range
protocol options (ICMP type and code fields, TCP flags, IP options and MSS)
interface the packet arrived from or left through
internal flow and connection marks
rate at which packets arrive and sequence numbers
packet arrival time
and much more!
This page contains both documentation and some basic examples.