MikroTik IPv6 setup: prefix from the provider, LAN and firewall
Last updated: 11 October 2026
More and more providers hand out IPv6. On a MikroTik router it takes three parts: ask the provider for a prefix, give part of it to your LAN, and add a firewall. The firewall is not optional: with IPv6 there is no NAT hiding your devices.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
RouterOS v6: enable the package
On v6, IPv6 is a separate package that is installed but often disabled:
/system package print
/system package enable ipv6
/system rebootOn v7 IPv6 is always there.
1. Ask the provider for a prefix
/ipv6 dhcp-client add interface=pppoe-out1 request=prefix pool-name=isp6 add-default-route=yes
/ipv6 dhcp-client printUse your WAN interface: pppoe-out1 for PPPoE, ether1 for a line that gives addresses by DHCP. When it shows bound with a prefix such as 2001:db8:1200::/56, the prefix is in the pool isp6.
2. Give the LAN addresses
/ipv6 address add address=::1/64 from-pool=isp6 interface=bridge advertise=yes
/ipv6 nd set [find default=yes] advertise-dns=yesThe router takes a /64 from the prefix for the bridge and announces it; devices make their own addresses from it. advertise-dns tells them to use the router for DNS; the router must answer DNS, see DNS setup.
3. The IPv6 firewall
Every device now has a public address. Without a firewall, the internet can reach each of them directly. The RouterOS default configuration includes rules like these; check that yours has them:
/ipv6 firewall filter
add chain=input action=accept connection-state=established,related,untracked
add chain=input action=drop connection-state=invalid
add chain=input action=accept protocol=icmpv6
add chain=input action=accept protocol=udp dst-port=546 src-address=fe80::/10 comment="DHCPv6 replies from the provider"
add chain=input action=drop in-interface-list=!LAN
add chain=forward action=accept connection-state=established,related,untracked
add chain=forward action=drop connection-state=invalid
add chain=forward action=accept protocol=icmpv6
add chain=forward action=drop in-interface-list=!LANICMPv6 must be allowed: IPv6 needs it to work (neighbour discovery, path MTU). The rules rely on the LAN interface list from the default configuration.
4. Check
/ipv6 address print
/ipv6 route print
/ping 2001:4860:4860::8888Then open an IPv6 test page from a computer on the LAN.
For PPPoE customers
To give each PPPoE customer their own IPv6 prefix, make a pool of /56 or /64 prefixes from the block your provider routes to you and name it in the PPP profile:
/ipv6 pool add name=cust-pd prefix=2001:db8:100::/48 prefix-length=56
/ppp profile set [find name=default] dhcpv6-pd-pool=cust-pdThe customer's router then asks for a prefix over DHCPv6 inside the PPPoE session.
Common problems
- The DHCPv6 client stays "searching": the provider does not offer prefixes on that interface, or the input rule for UDP 546 is missing.
- Devices get an address but no internet: no default IPv6 route; check
add-default-route=yesor the provider's router advertisements. - Some sites slow, others fine: ICMPv6 is blocked somewhere, which breaks path MTU discovery.
Questions and answers
Does MikroTik support IPv6 prefix delegation?
Yes. The DHCPv6 client with request=prefix receives a delegated prefix into a pool, and LAN addresses are taken from that pool.
Do I need NAT for IPv6 on MikroTik?
No. Devices get public addresses; the firewall does the job of protecting them.
Why is my MikroTik DHCPv6 client not getting a prefix?
The provider may not offer one on that interface, or the firewall drops the DHCPv6 replies on UDP port 546.