MikroTik load balancing with two internet lines (PCC)
Last updated: 2 October 2026
PCC (per connection classifier) spreads your users across two internet lines so both are used at once. This guide is the standard two-line setup, with the route commands for RouterOS v6 and v7.
Want it done for you? The free 2 WAN load balancing script generator builds this whole setup for your two ports - download the .rsc and paste it into Winbox.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
In the examples ether1 is line 1 (gateway 192.168.1.1), ether2 is line 2 (gateway 192.168.2.1) and bridge is the LAN.
1. Turn off FastTrack
FastTrack skips the marking rules below.
/ip firewall filter disable [find action=fasttrack-connection]2. Mark connections and routes
/ip firewall mangle
add chain=prerouting in-interface=ether1 connection-mark=no-mark action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=ether2 connection-mark=no-mark action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/0 action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/1 action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=prerouting in-interface=bridge connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2
add chain=output connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=output connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2On RouterOS v7, create the two routing tables before these rules (next step).
3a. Routes on RouterOS v7
/routing table add name=to_WAN1 fib
/routing table add name=to_WAN2 fib
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-table=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=23b. Routes on RouterOS v6
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 routing-mark=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=192.168.1.1 distance=1
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 distance=24. NAT on both lines
/ip firewall nat add chain=srcnat out-interface=ether1 action=masquerade
/ip firewall nat add chain=srcnat out-interface=ether2 action=masqueradeLines of different speed
For a 2:1 split use three classes: 3/0 and 3/1 to line 1, 3/2 to line 2.
Good to know
- PCC balances connections, not bytes. One big download uses one line.
- If a line fails, add failover checks so its users move to the other.
- Banking sites are happier with
both-addresses, which keeps a user on one line per site.
Questions and answers
Does PCC double my speed?
It doubles the total capacity for many users. A single connection still uses one line.
Why does load balancing stop working after a while?
Usually FastTrack is still enabled, or the marking rules sit below other rules that catch the traffic first.
Can I load balance more than two lines?
Yes. Use one class per line (3/0, 3/1, 3/2 for three lines) and one routing table per line.