/ip firewall raw
add action=drop chain=prerouting dst-port=53 protocol=udp
add action=drop chain=prerouting dst-port=21,22,23,8291 protocol=tcp \
src-address-list=black_list
add action=add-src-to-address-list address-list=black_list \
address-list-timeout=4w2d chain=prerouting dst-port=21,22,23,8291 \
protocol=tcp src-address-list=ssh_stage3
add action=add-src-to-address-list address-list=ssh_stage3 \
address-list-timeout=1m chain=prerouting dst-port=21,22,23,8291 protocol=\
tcp src-address-list=ssh_stage2
add action=add-src-to-address-list address-list=ssh_stage2 \
address-list-timeout=1m chain=prerouting dst-port=21,22,23,8291 protocol=\
tcp src-address-list=ssh_stage1
add action=add-src-to-address-list address-list=ssh_stage1 \
address-list-timeout=1m chain=prerouting dst-port=21,22,23,8291 protocol=\
tcp src-address-list=!MGMT-ALLOW