MikroTik internet sharing: WAN, LAN, DHCP and NAT from scratch
Last updated: 2 October 2026
Sharing an internet line needs five things on a MikroTik: an address on the WAN side, an address on the LAN side, a DHCP server, DNS, and one NAT rule. This guide builds them in order on an empty router, then lists what to check when devices connect but have no internet.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
In the examples ether1 goes to the modem or ISP and bridge is your LAN (see bridge setup). A router with the default configuration already has all of this; the commands are for a router that was reset empty or set up by hand.
1. The WAN side
The modem or ISP gives an address automatically (most common):
/ip dhcp-client add interface=ether1 disabled=no
/ip dhcp-client printThe status must read bound. The default route and the DNS servers come with it.
The ISP gave you a fixed address:
/ip address add address=203.0.113.10/24 interface=ether1
/ip route add dst-address=0.0.0.0/0 gateway=203.0.113.1
/ip dns set servers=1.1.1.1,8.8.8.8The ISP gave you a username and password: that is PPPoE. Follow PPPoE client setup and use pppoe-out1 wherever this guide says ether1.
2. The LAN address
/ip address add address=192.168.88.1/24 interface=bridgeThe LAN range must be different from the range on the WAN side. If your modem already uses 192.168.88.x, pick another, for example 192.168.50.1/24.
3. A DHCP server for your devices
/ip pool add name=lan-pool ranges=192.168.88.10-192.168.88.254
/ip dhcp-server add name=lan-dhcp interface=bridge address-pool=lan-pool disabled=no
/ip dhcp-server network add address=192.168.88.0/24 gateway=192.168.88.1 dns-server=192.168.88.1More options in DHCP server setup.
4. DNS
/ip dns set allow-remote-requests=yesThe router now answers DNS for the LAN. Keep port 53 closed from the internet; see DNS setup.
5. The masquerade rule
/ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade comment="share internet"This is the rule that does the sharing. Everything leaving through ether1 is sent with the router's own WAN address, and the replies are handed back to the right device. Without it your devices reach the router and nothing beyond.
Then protect the router before you leave it online: basic firewall.
Connected but no internet: check in this order
Work from the router outwards. Run each test in the router's terminal and stop at the first one that fails.
1. Does the router have a route?
/ip route print where dst-address=0.0.0.0/0
/ping 8.8.8.8 count=4There must be one active default route. No route: the DHCP client is not bound, the PPPoE session is down, or the static gateway is missing. Route present but no ping replies: the problem is the modem or the line, not your settings.
2. Does the NAT rule name the right interface?
/ip firewall nat print statsThe masquerade rule must have out-interface set to the interface that really carries the internet. The most common mistake is a rule for ether1 when the line is pppoe-out1, or a rule left behind from an old setup. The packet counter of the right rule rises while a device tries to browse; a counter that stays at zero means the rule does not match.
3. Does DNS work?
:put [:resolve mikrotik.com]
/ip dns printIf pinging 8.8.8.8 works but this fails, the router has no DNS servers. If the router resolves names but clients do not, allow-remote-requests is off or the DHCP network hands out the wrong DNS server.
4. Does the client have the right gateway?
/ip dhcp-server lease print
/ip dhcp-server network printOn the device, look at its network details: the address must be in your LAN range, and gateway and DNS must be the router's LAN address. A device with a 169.254.x.x address got no answer from DHCP. A device with a gateway from another range is listening to a second DHCP server, often a Wi-Fi router plugged in by its LAN port.
5. Is the firewall dropping it?
/ip firewall filter print stats where chain=forwardA forward drop rule with a rising counter is stopping your own traffic. Disable it for a moment to confirm, then correct its interface.
What to do next
- Two lines: failover.
- Fair speeds: bandwidth limit per user.
- A login per user: hotspot setup.
Where RadiusNest fits
This setup shares the line with anyone who can plug in or knows the Wi-Fi password. RadiusNest comes in when you want each user to log in: add a hotspot or a PPPoE server on top of the working internet above, paste one command, and logins are checked centrally with the speed, data and end date of each customer's package. The router needs no public IP address for that.
Start the free trial See pricing
Questions and answers
What does masquerade do?
It replaces the private address of your devices with the router's WAN address on the way out, so one internet address can serve the whole network.
Should I use masquerade or src-nat?
Masquerade suits a WAN address that can change, such as DHCP or PPPoE. With a fixed public address, src-nat with to-addresses does the same job and is slightly lighter.
The router can ping the internet but my devices cannot. Why?
The masquerade rule is missing or points at the wrong out-interface, or the devices have the wrong gateway. Check the NAT counters and the DHCP network settings.