RadiusNest › Guides

MikroTik internet sharing: WAN, LAN, DHCP and NAT from scratch

Last updated: 2 October 2026

Sharing an internet line needs five things on a MikroTik: an address on the WAN side, an address on the LAN side, a DHCP server, DNS, and one NAT rule. This guide builds them in order on an empty router, then lists what to check when devices connect but have no internet.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

In the examples ether1 goes to the modem or ISP and bridge is your LAN (see bridge setup). A router with the default configuration already has all of this; the commands are for a router that was reset empty or set up by hand.

1. The WAN side

The modem or ISP gives an address automatically (most common):

/ip dhcp-client add interface=ether1 disabled=no
/ip dhcp-client print

The status must read bound. The default route and the DNS servers come with it.

The ISP gave you a fixed address:

/ip address add address=203.0.113.10/24 interface=ether1
/ip route add dst-address=0.0.0.0/0 gateway=203.0.113.1
/ip dns set servers=1.1.1.1,8.8.8.8

The ISP gave you a username and password: that is PPPoE. Follow PPPoE client setup and use pppoe-out1 wherever this guide says ether1.

2. The LAN address

/ip address add address=192.168.88.1/24 interface=bridge

The LAN range must be different from the range on the WAN side. If your modem already uses 192.168.88.x, pick another, for example 192.168.50.1/24.

3. A DHCP server for your devices

/ip pool add name=lan-pool ranges=192.168.88.10-192.168.88.254
/ip dhcp-server add name=lan-dhcp interface=bridge address-pool=lan-pool disabled=no
/ip dhcp-server network add address=192.168.88.0/24 gateway=192.168.88.1 dns-server=192.168.88.1

More options in DHCP server setup.

4. DNS

/ip dns set allow-remote-requests=yes

The router now answers DNS for the LAN. Keep port 53 closed from the internet; see DNS setup.

5. The masquerade rule

/ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade comment="share internet"

This is the rule that does the sharing. Everything leaving through ether1 is sent with the router's own WAN address, and the replies are handed back to the right device. Without it your devices reach the router and nothing beyond.

Then protect the router before you leave it online: basic firewall.

Connected but no internet: check in this order

Work from the router outwards. Run each test in the router's terminal and stop at the first one that fails.

1. Does the router have a route?

/ip route print where dst-address=0.0.0.0/0
/ping 8.8.8.8 count=4

There must be one active default route. No route: the DHCP client is not bound, the PPPoE session is down, or the static gateway is missing. Route present but no ping replies: the problem is the modem or the line, not your settings.

2. Does the NAT rule name the right interface?

/ip firewall nat print stats

The masquerade rule must have out-interface set to the interface that really carries the internet. The most common mistake is a rule for ether1 when the line is pppoe-out1, or a rule left behind from an old setup. The packet counter of the right rule rises while a device tries to browse; a counter that stays at zero means the rule does not match.

3. Does DNS work?

:put [:resolve mikrotik.com]
/ip dns print

If pinging 8.8.8.8 works but this fails, the router has no DNS servers. If the router resolves names but clients do not, allow-remote-requests is off or the DHCP network hands out the wrong DNS server.

4. Does the client have the right gateway?

/ip dhcp-server lease print
/ip dhcp-server network print

On the device, look at its network details: the address must be in your LAN range, and gateway and DNS must be the router's LAN address. A device with a 169.254.x.x address got no answer from DHCP. A device with a gateway from another range is listening to a second DHCP server, often a Wi-Fi router plugged in by its LAN port.

5. Is the firewall dropping it?

/ip firewall filter print stats where chain=forward

A forward drop rule with a rising counter is stopping your own traffic. Disable it for a moment to confirm, then correct its interface.

What to do next

Where RadiusNest fits

This setup shares the line with anyone who can plug in or knows the Wi-Fi password. RadiusNest comes in when you want each user to log in: add a hotspot or a PPPoE server on top of the working internet above, paste one command, and logins are checked centrally with the speed, data and end date of each customer's package. The router needs no public IP address for that.

Start the free trial See pricing

Questions and answers

What does masquerade do?

It replaces the private address of your devices with the router's WAN address on the way out, so one internet address can serve the whole network.

Should I use masquerade or src-nat?

Masquerade suits a WAN address that can change, such as DHCP or PPPoE. With a fixed public address, src-nat with to-addresses does the same job and is slightly lighter.

The router can ping the internet but my devices cannot. Why?

The masquerade rule is missing or points at the wrong out-interface, or the devices have the wrong gateway. Check the NAT counters and the DHCP network settings.

Related guides

Start the free trial See pricing