/ip firewall raw
add action=add-src-to-address-list address-list=hackers address-list-timeout=1w \
chain=prerouting dst-port=21,22,23,80,110,135,139,143,445,1433,3389,8080 \
in-interface-list=WAN log=yes log-prefix=fix protocol=tcp \
src-address-list=!BOGON
/ip firewall filter
add action=add-src-to-address-list address-list=Honeypot address-list-timeout=\
1w chain=input comment="Honeypot list" dst-address-list=!BOGON dst-port=\
21,22,23,80,110,135,139,143,445,1433,3389,8080 in-interface-list=WAN log=\
yes protocol=tcp