MikroTik load balancing with 3 or 4 internet lines
Last updated: 11 October 2026
PCC works the same way with three or four lines as with two: one class per share, one routing table per line, one NAT rule per line. This guide shows three lines and how to weight them when they are not the same speed.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
Lines: ether1 gateway 192.168.1.1, ether2 gateway 192.168.2.1, ether3 gateway 192.168.3.1. LAN: bridge. Two lines only? See two-line PCC.
1. FastTrack off
/ip firewall filter disable [find action=fasttrack-connection]2. Marks
/ip firewall mangle
add chain=prerouting in-interface=ether1 connection-mark=no-mark action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=ether2 connection-mark=no-mark action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=ether3 connection-mark=no-mark action=mark-connection new-connection-mark=WAN3_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:3/0 action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:3/1 action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:3/2 action=mark-connection new-connection-mark=WAN3_conn
add chain=prerouting in-interface=bridge connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=prerouting in-interface=bridge connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2
add chain=prerouting in-interface=bridge connection-mark=WAN3_conn action=mark-routing new-routing-mark=to_WAN3
add chain=output connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=output connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2
add chain=output connection-mark=WAN3_conn action=mark-routing new-routing-mark=to_WAN3On v7, create the tables (next step) before these rules.
3. Routes, each with a spare
RouterOS v7:
/routing table add name=to_WAN1 fib
/routing table add name=to_WAN2 fib
/routing table add name=to_WAN3 fib
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=to_WAN1 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN1 distance=2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN2 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=192.168.3.1 routing-table=to_WAN2 distance=2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.3.1 routing-table=to_WAN3 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=to_WAN3 distance=2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=2 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=192.168.3.1 distance=3 check-gateway=pingRouterOS v6: the same lines, with routing-mark=to_WAN1 (and so on) in place of routing-table=…, and no /routing table commands.
check-gateway=ping notices a dead modem. It does not notice a modem that answers while the internet behind it is down; for that, check a host on the internet as in failover.
4. NAT
/ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade
/ip firewall nat add chain=srcnat out-interface=ether2 action=masquerade
/ip firewall nat add chain=srcnat out-interface=ether3 action=masqueradeLines of different speeds
PCC shares connections by class. Give a faster line more classes. For lines of 100, 50 and 50 Mbit/s, use four classes and send two of them to line 1:
| Class | Mark |
|---|---|
4/0, 4/1 | WAN1_conn |
4/2 | WAN2_conn |
4/3 | WAN3_conn |
That is four PCC rules instead of three. Speeds rarely divide this neatly; round to the nearest simple share.
Four lines
Add ether4 the same way: a fourth input mark, classes 4/0 to 4/3, a fourth table and route, a fourth NAT rule.
Good to know
- Each new connection picks a line; a single download never gets the sum of all lines.
both-addresseskeeps a user on the same line for the same site, which keeps banking and game sessions happy.- Speed limits for the whole network should add up all lines; see PCQ.
- Other ways to split traffic, and when they fit: PCC, ECMP, Nth and bonding compared.
Two lines with fixed or DHCP addresses? The free 2 WAN load balancing script generator writes the whole setup for your ports.
Questions and answers
How many WAN lines can MikroTik load balance?
There is no small fixed limit; each line needs one class, one routing table and one NAT rule. Three and four lines are common.
How do I give a faster line more traffic in PCC?
Use more classes and send more of them to the faster line, for example 4 classes with 2 going to the line that is twice as fast.
What happens when one of three lines fails?
With a spare route in each table, the users on the failed line move to the next line and come back when it returns.