کد PHP:
/ip firewall filter
add action=drop chain=forward disabled=no in-interface=ether1 layer7-protocol=\
Rule out-interface=ether1 protocol=tcp
add action=drop chain=forward disabled=no in-interface=ether2 layer7-protocol=\
Rule out-interface=ether2 protocol=tcp
add action=accept chain=forward comment="..::Port 8291::.." disabled=no \
layer7-protocol=Rule port=8291 protocol=tcp
add action=accept chain=forward comment="..::Port 1024::.." disabled=no \
layer7-protocol=Rule port=1024 protocol=tcp
add action=accept chain=forward comment="..::Port 21::.." disabled=no \
in-interface=ether2 layer7-protocol=Rule out-interface=ether2 port=21 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether1 \
layer7-protocol=Rule out-interface=ether1 port=21 protocol=tcp
add action=accept chain=forward comment="..::Port 20::.." disabled=no \
in-interface=ether1 layer7-protocol=Rule out-interface=ether1 port=20 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether2 \
layer7-protocol=Rule out-interface=ether2 port=20 protocol=tcp
add action=accept chain=forward comment="..::Port 22::.." disabled=no \
in-interface=ether1 layer7-protocol=Rule out-interface=ether1 port=22 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether2 \
layer7-protocol=Rule out-interface=ether2 port=22 protocol=tcp
add action=accept chain=forward comment="..::Port 53::.." disabled=no \
in-interface=ether1 layer7-protocol=Rule out-interface=ether1 port=53 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether2 \
layer7-protocol=Rule out-interface=ether2 port=53 protocol=tcp
add action=accept chain=forward comment="..::Port 80::.." disabled=no \
in-interface=ether2 layer7-protocol=Rule out-interface=ether2 port=80 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether1 \
layer7-protocol=Rule out-interface=ether1 port=80 protocol=tcp
add action=accept chain=forward comment="..::Port 443::.." disabled=no \
in-interface=ether1 layer7-protocol=Rule out-interface=ether1 port=443 \
protocol=tcp
add action=accept chain=forward disabled=no in-interface=ether2 \
layer7-protocol=Rule out-interface=ether2 port=443 protocol=tcp
در لایه 7 هم باید یه Rule اضافه کنید