kei is a Hex Lite, the cheapest router that Mikrotik sells with PoE powering. I want a zero-maintenance appliance that can run Adlist, as a good-enough alternative to Pihole. Pihole is excellent, but I want something even simpler, and the Adlist feature is indeed good enough for me.
neru is a hEX lite:
Homepage: https://mikrotik.com/product/hex_s_2025
- Product code: RB750r2
Contents
Features and uses
- 5x 100M RJ45 ports
- PoE powered
- mibsbe CPU, so no containers for you!
That's correct, it's only Fast Ethernet, not even gigabit!
Hardware
- CPU: QCA9533
Switch chip: QCA9533 according to homepage, but the mgmt UI says it's an "Atheros 8227" (https://help.mikrotik.com/docs/spaces/ROS/pages/15302988/Switch+Chip+Features)
A surprisingly decent switch chip for such a cheap device, it does hardware STP and VLAN filtering sensibly.
Config dump
Taken from a /export on the CLI.
/interface vlan add interface=ether1 name=VLAN10_GENERAL vlan-id=10 add interface=ether1 name=VLAN11_MGMT vlan-id=11 add interface=ether1 name=VLAN42_DN42_LAN vlan-id=42 /interface list add comment=defconf name=WAN add comment=defconf name=LAN /user group add name=mikrodash policy=read,test,api,!local,!telnet,!ssh,!ftp,!reboot,!write,!policy,!winbox,!password,!web,!sniff,!sensitive,!romon,!rest-api /ip neighbor discovery-settings set discover-interface-list=all lldp-mac-phy-config=yes lldp-max-frame-size=yes lldp-vlan-info=yes /interface list member add interface=VLAN10_GENERAL list=LAN add interface=VLAN11_MGMT list=LAN add interface=VLAN42_DN42_LAN list=WAN /ip address add address=172.22.124.50/28 interface=VLAN42_DN42_LAN network=172.22.124.48 add address=192.168.11.8/24 interface=VLAN11_MGMT network=192.168.11.0 /ip dhcp-client add interface=VLAN10_GENERAL name=client1 # You need to set a bigger cache so it can pull the adlist and ingest it /ip dns set allow-remote-requests=yes cache-size=20480KiB servers=8.8.8.8 /ip dns adlist add ssl-verify=no url=https://raw.githubusercontent.com/IgorKha/mikrotik-adlist/refs/heads/main/hosts/steven_blacks_list.txt /ip dns static add address=172.22.124.49 name=ns1.thighhighs.dn42 ttl=1h type=A add address=fdd8:8086:2501:5353::2 name=ns1.thighhighs.dn42 ttl=1h type=AAAA add address=172.22.124.50 name=ns2.thighhighs.dn42 ttl=1h type=A add address=fdd8:8086:2501:5353::3 name=ns2.thighhighs.dn42 ttl=1h type=AAAA /ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=drop chain=input comment="drop udp/17500" dst-port=17500 protocol=udp add action=drop chain=input comment="drop udp/138" dst-port=138 protocol=udp add action=drop chain=input comment="drop udp/137" dst-port=137 protocol=udp add action=drop chain=input comment="drop udp/1900 SSDP/UPNP" dst-port=1900 protocol=udp add action=drop chain=input comment="drop udp/68 DHCP" dst-port=68 protocol=udp add action=drop chain=input comment="drop udp/9999" dst-port=9999 protocol=udp add action=drop chain=input comment="drop udp/9478 GHome" dst-port=9478 protocol=udp add action=accept chain=input comment="accept ND" dst-port=5678 protocol=udp add action=accept chain=input comment="accept remaining" log=yes log-prefix="accepted end of chain" add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="drop everything else" /ipv6 route add disabled=no distance=1 dst-address=fd00::/8 gateway=fdd8:8086:2501:10::62%VLAN42_DN42_LAN pref-src="" routing-table=main scope=30 target-scope=10 /ip service set ftp disabled=yes set telnet disabled=yes set www disabled=yes /ip ssh set host-key-size=4096 host-key-type=ed25519 password-authentication=yes strong-crypto=yes /ipv6 address add address=fdd8:8086:2501:5353::3 interface=VLAN42_DN42_LAN add address=fdfd:2501:2762:11::8 interface=VLAN11_MGMT add address=fdd8:8086:2501:10::50 interface=VLAN42_DN42_LAN /ipv6 firewall address-list add address=::/128 comment="defconf: unspecified address" list=bad_ipv6 add address=::1/128 comment="defconf: lo" list=bad_ipv6 add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6 add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6 add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6 add address=100::/64 comment="defconf: discard only " list=bad_ipv6 add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6 add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6 add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6 /ipv6 firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6 add action=accept chain=input comment="defconf: accept UDP traceroute" dst-port=33434-33534 protocol=udp add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10 add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec add action=drop chain=input comment="defconf: drop everything else not coming from LAN" disabled=yes in-interface-list=!LAN add action=fasttrack-connection chain=forward comment="defconf: fasttrack6" connection-state=established,related add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6 add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6 add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6 add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6 add action=accept chain=forward comment="defconf: accept HIP" protocol=139 add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN /snmp set contact=Furinkan enabled=yes location="Home" /system clock set time-zone-name=Australia/Sydney /system identity set name=kei /system ntp client set enabled=yes /system ntp client servers add address=au.pool.ntp.org add address=pool.ntp.org /system routerboard settings set silent-boot=yes