MikroTik load balancing with two PPPoE internet lines
Last updated: 11 October 2026
Many fibre and DSL lines need a PPPoE login on your router. Balancing two of them works like any other PCC load balancing, with two differences: the gateways are the PPPoE interfaces, and a line that drops takes its routes away by itself.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
In the examples line 1 arrives on ether1, line 2 on ether2, and the LAN is bridge.
1. Two PPPoE clients
/interface pppoe-client add name=pppoe-out1 interface=ether1 user=LINE1-USER password=LINE1-PASS add-default-route=yes default-route-distance=1 use-peer-dns=yes disabled=no
/interface pppoe-client add name=pppoe-out2 interface=ether2 user=LINE2-USER password=LINE2-PASS add-default-route=yes default-route-distance=2 disabled=no
/interface pppoe-client printBoth should show R (running). The two default routes with distance 1 and 2 are the fallback for traffic the rules below do not mark, and they give simple failover at the same time. Details of the client: PPPoE client setup.
2. Turn off FastTrack
/ip firewall filter disable [find action=fasttrack-connection]FastTracked connections skip the marking rules, and balancing quietly stops.
3. Mark connections and routes
/ip firewall mangle
add chain=prerouting in-interface=pppoe-out1 connection-mark=no-mark action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=pppoe-out2 connection-mark=no-mark action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/0 action=mark-connection new-connection-mark=WAN1_conn
add chain=prerouting in-interface=bridge connection-mark=no-mark dst-address-type=!local per-connection-classifier=both-addresses:2/1 action=mark-connection new-connection-mark=WAN2_conn
add chain=prerouting in-interface=bridge connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=prerouting in-interface=bridge connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2
add chain=output connection-mark=WAN1_conn action=mark-routing new-routing-mark=to_WAN1
add chain=output connection-mark=WAN2_conn action=mark-routing new-routing-mark=to_WAN2On RouterOS v7, create the routing tables in step 4 before pasting these rules.
4. Routes
RouterOS v7:
/routing table add name=to_WAN1 fib
/routing table add name=to_WAN2 fib
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-table=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-table=to_WAN1 distance=2
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-table=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-table=to_WAN2 distance=2RouterOS v6:
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-mark=to_WAN1
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-mark=to_WAN1 distance=2
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out2 routing-mark=to_WAN2
/ip route add dst-address=0.0.0.0/0 gateway=pppoe-out1 routing-mark=to_WAN2 distance=2Each table has its own line first and the other line as a spare with distance 2. When a PPPoE session drops, its interface goes down, its routes become inactive, and the marked traffic uses the spare until the line is back.
5. NAT on both
/ip firewall nat add chain=srcnat out-interface=pppoe-out1 action=masquerade
/ip firewall nat add chain=srcnat out-interface=pppoe-out2 action=masquerade6. MSS for PPPoE
PPPoE has a smaller MTU than Ethernet. If some websites hang half-loaded, see PPPoE MTU and MSS; the usual fix is one change-mss rule per PPPoE line.
Two accounts on one cable
Some providers deliver two PPPoE accounts on the same port. Two clients on the same interface share one MAC address, which many providers do not accept. On RouterOS v7 make a second interface with its own MAC address and put the second client on it:
/interface macvlan add name=macvlan1 interface=ether1
/interface pppoe-client set pppoe-out2 interface=macvlan1Check
/ip firewall mangle print stats
/interface monitor-traffic pppoe-out1,pppoe-out2Both lines should carry traffic once several users are online. A single download stays on one line: PCC balances connections, not bytes. For lines of different speeds and more than two lines, see 3 and 4 WAN load balancing.
Two lines with fixed or DHCP addresses? The free 2 WAN load balancing script generator writes the whole setup for your ports.
Questions and answers
Can MikroTik load balance two PPPoE connections?
Yes. Mark connections with PCC and route each mark out of its own PPPoE interface, as above. It works on RouterOS v6 and v7.
Do I need check-gateway with PPPoE lines?
Not for a dropped session: the PPPoE interface goes down and its routes stop at once. A line that stays connected but carries no traffic needs a check on a host, as in the failover guide.
Can two PPPoE accounts from one provider be bonded into one faster connection?
Only if the provider supports it. Otherwise PCC spreads your users over both, which is what most ISPs do.