RadiusNest › Guides

MikroTik load balancing with two internet lines (PCC)

Last updated: 2 October 2026

PCC (per connection classifier) spreads your users across two internet lines so both are used at once. This guide is the standard two-line setup, with the route commands for RouterOS v6 and v7.

Want it done for you? The free 2 WAN load balancing script generator builds this whole setup for your two ports - download the .rsc and paste it into Winbox.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

In the examples ether1 is line 1 (gateway 192.168.1.1), ether2 is line 2 (gateway 192.168.2.1) and bridge is the LAN.

1. Turn off FastTrack

FastTrack skips the marking rules below.

/ip firewall filter disable [find action=fasttrack-connection]

2. Mark connections and routes

/ip firewall mangle
add chain=prerouting in-interface=ether1 connection-mark=no-mark action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=ether2 connection-mark=no-mark action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/0 action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/1 action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=prerouting in-interface=bridge connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2
add chain=output connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=output connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2

On RouterOS v7, create the two routing tables before these rules (next step).

3a. Routes on RouterOS v7

/routing table add name=to_WAN1 fib
/routing table add name=to_WAN2 fib
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=2

3b. Routes on RouterOS v6

/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=2

4. NAT on both lines

/ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade
/ip firewall nat add chain=srcnat out-interface=ether2 action=masquerade

Lines of different speed

For a 2:1 split use three classes: 3/0 and 3/1 to line 1, 3/2 to line 2.

Good to know

  • PCC balances connections, not bytes. One big download uses one line.
  • If a line fails, add failover checks so its users move to the other.
  • Banking sites are happier with both-addresses, which keeps a user on one line per site.

Questions and answers

Does PCC double my speed?

It doubles the total capacity for many users. A single connection still uses one line.

Why does load balancing stop working after a while?

Usually FastTrack is still enabled, or the marking rules sit below other rules that catch the traffic first.

Can I load balance more than two lines?

Yes. Use one class per line (3/0, 3/1, 3/2 for three lines) and one routing table per line.

Related guides

Start the free trial See pricing