firewall_baseline
Applies a MikroTik-defconf-style IPv4 firewall with input, forward, and NAT rules. Stops and lists existing filters to avoid conflicts; set replace_existing to override.
Instructions
Apply a MikroTik-defconf-style IPv4 firewall: input: accept established/related/untracked, drop invalid, accept ICMP, accept WireGuard ports, drop everything not from LAN. forward: fasttrack, accept established/related, drop invalid, drop new WAN connections that aren't port-forwards. nat: masquerade out WAN (if none exists). If the router already has other filter rules, the tool stops and lists them; set replace_existing=True to replace them (rules tagged mcp-wifi/mcp-wg are kept).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | router | |
| add_nat | No | ||
| dry_run | No | ||
| wan_interface | No | ||
| lan_interfaces | No | ||
| replace_existing | No | ||
| rollback_minutes | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |