http://arav.i2p/stuff/article/hardening_mikrotik
In a terminal: > ip/firewall/filter/add place-before=<last rule number> chain=input action=add-src-to-address-list protocol=tcp psd=21,3s,3,1 address-list=whores address-list-timeout=1h in-interface-list=WAN . And then, to actually restrict access, we need another rule.