RadiusNest › Guides

MikroTik: limit YouTube and video speed without blocking it

Last updated: 11 October 2026

Video is usually the biggest load on a shared line. Blocking YouTube makes customers angry; giving all video a fair share in the evening keeps browsing and calls fast for everyone. This guide limits video connections with mangle and a queue.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

How it works

YouTube video comes from servers whose names end in googlevideo.com. When a phone opens an encrypted connection, the first packet still carries that name (the TLS host). The router reads it, notes the server's address in a list for a day, marks every connection to the listed addresses, and a queue limits the marked traffic.

1. Collect video servers

/ip firewall mangle add chain=forward protocol=tcp dst-port=443 tls-host=*.googlevideo.com action=add-dst-to-address-list address-list=video address-list-timeout=1d

Facebook and Instagram media come from *.fbcdn.net (pictures as well as video). Add another rule like this one if you want them in the same limit.

2. Make video use TCP

Phones and Chrome often fetch YouTube over QUIC (UDP 443), where the router cannot read the name. Refusing QUIC to the listed servers makes the app fall back to normal HTTPS, which the rule above can see:

/ip firewall filter add chain=forward protocol=udp dst-port=443 dst-address-list=video action=reject reject-with=icmp-port-unreachable comment="video over TCP"

If you prefer, drop all QUIC with protocol=udp dst-port=443 and no list; every site falls back to TCP, at the cost of slightly slower first loads.

3. Mark video connections and packets

/ip firewall mangle
add chain=forward dst-address-list=video connection-mark=no-mark action=mark-connection new-connection-mark=video_conn passthrough=yes
add chain=forward connection-mark=video_conn action=mark-packet new-packet-mark=video_pkt passthrough=no

4. Turn off FastTrack

/ip firewall filter disable [find action=fasttrack-connection]

FastTracked connections skip mangle and queues, and FastTrack can take over a connection before the packet with the server name arrives, so the name is never seen. This method needs FastTrack off. On a busy router, watch the CPU afterwards (high CPU). See also mangle explained.

5. The limit

/queue simple add name=video target=192.168.88.0/24 packet-marks=video_pkt max-limit=5M/30M comment="all video together"

5M/30M is the total for all video on the network: 5 Mbit/s up, 30 Mbit/s down. Simple queues are checked from the top, so move this queue above your per-user queues, or they catch the traffic first.

To share the video limit equally between users instead of first come first served, use PCQ queue types in the queue (queue=pcq-upload-default/pcq-download-default); see PCQ.

Only in the evening

Leave the queue in place and change its limit by time with the scheduler; see time-based speed.

Check

/ip firewall address-list print count-only where list=video
/queue simple print stats where name=video

Limits of this method

  • Names and servers change; the list rebuilds itself every day, but a new service needs a new rule.
  • Devices that use encrypted names (ECH), or apps that wrap all their traffic in encryption, hide the name, and their video is not caught.
  • A customer who pays for more should get more: package speeds remain the fair way to sell. This rule only keeps evening video from crowding out everything else.

Questions and answers

How do I limit YouTube on MikroTik without blocking it?

Collect googlevideo.com servers into an address list with a tls-host mangle rule, mark connections to them, and limit the marked packets with a queue.

Why does my YouTube limit not work?

Usually QUIC (UDP 443) carries the video, FastTrack is still on, or a per-user queue above the video queue catches the traffic first.

Which RouterOS versions support tls-host?

RouterOS 6.41 and newer, and all v7 versions.

Related guides

Start the free trial See pricing