RadiusNest › Guides › Free tool

MikroTik 2 WAN load balancing script generator

Updated: 7 October 2026 · RouterOS 7 · Free until 6 November 2026

Two internet lines on one MikroTik router, balanced with PCC and with automatic failover. Enter your two WAN ports and their addresses, and download a ready .rsc script to paste into Winbox. The same setup that the RadiusNest dashboard builds for ISPs, free on this page for 30 days.

Your two lines

The free period on this page has ended. The generator lives on in RadiusNest, where every account starts with a free trial.

Start the free trial Open the generator in RadiusNest

WAN 1 - the main line

The router port the first internet line is plugged into.
With its prefix, exactly as the provider gave it.
The provider's address on that line.

WAN 2 - the second line

How to share the traffic

Give the faster line the bigger share. Each customer-to-server pair always stays on one line.
A public address the router pings through WAN 1. No answer = WAN 1 is treated as down.
Must be a different address from the WAN 1 check host.
Nothing is sent anywhere: the script is made in your browser.

Your script

  1. Plug both lines in and open the router in Winbox (RouterOS 7).
  2. Open New Terminal, paste the whole script and press Enter. Or upload the .rsc in Files and run /import file-name=….
  3. Within a minute, IP › Routes shows both default routes active. Firewall › Connections shows wan1-conn and wan2-conn taking turns.

The script turns FastTrack off and disables any other static default route in the main table - load balancing cannot work with either. Running it again replaces its own rules only (they are all tagged RN-LB).


What the script sets up

This is the recursive-routes-plus-PCC method, the one that holds up on real ISP routers, built from the two ports you name:

StepWhat it addsWhy
WAN addressesYour static address and gateway, or a DHCP client that adds no default routeThe load-balancing routes decide where traffic goes, not the DHCP lease
Routing tablesto-wan1 and to-wan2One table per line, so a marked connection can be sent out a chosen WAN
Check hosts8.8.8.8 reachable only through WAN 1, 1.1.1.1 only through WAN 2Each line gets its own internet-reachability test
Recursive default routesSix routes with check-gateway=ping and target-scope=11: primary and backup in main, to-wan1 and to-wan2A route exists only while its line really reaches the internet - that is the failover, both ways
NATMasquerade on each WAN portCustomers go out with the address of the line they were given
Mangle (8 rules)Connections arriving on a WAN are marked for it; new LAN connections are split by per-connection-classifier both-addresses; marked connections are routed through their table, in prerouting and in outputThis is the PCC load balancing itself, including the router's own replies

The LAN side is "everything that did not come in on a WAN port", so hotspot, PPPoE, VLAN and bridge customers are all balanced without naming them. Destinations that are the router itself or a private network stay out of it, so your own networks keep talking to each other through the main table.

How to use it

  1. Type the port of each line (ether1, ether2, sfp1, an LTE interface - any name RouterOS shows).
  2. For a line with a fixed address from the provider, enter the address with its prefix (203.0.113.2/30) and the gateway. For a line that gets its address automatically, choose DHCP.
  3. Pick the share. Equal lines: 1 : 1. A 100 Mbps line next to a 50 Mbps line: 2 : 1 in favour of the faster one.
  4. Generate, download the .rsc or copy the text, and paste it into Winbox › New Terminal. Every step logs ok or FAILED in the router log, so you can see exactly what happened.

Before you change a live router: take a backup (how) and know how you will reach the router if the WAN addresses change. The script disables other static default routes and FastTrack, and removes a DHCP client from a port you set to static.

Questions and answers

Is the MikroTik load balancing script free?

Yes. Until 06 November 2026 anyone can generate and download it here without an account. After that it stays available inside RadiusNest, where every account starts with a free trial.

Which RouterOS version does it need?

RouterOS 7. The script uses routing tables and recursive routes the way RouterOS 7 expects them. For RouterOS 6 the same idea works but the commands are different; see the PCC guide linked below.

Does it work with hotspot and PPPoE customers?

Yes. The mangle rules balance everything that did not come in on a WAN port: hotspot, PPPoE, VLAN and bridge customers alike. Traffic to the router itself and to private networks is left alone, so routing between your own networks keeps working.

Does it do failover too?

Yes. Every default route pings its check host (8.8.8.8 through WAN 1, 1.1.1.1 through WAN 2). A line that cannot reach the internet drops out within about 30 seconds, even if the cable stays up, and comes back by itself.

Can I run the script more than once?

Yes. Everything it adds carries the comment RN-LB. A second run first removes the previous run and nothing else of yours, so you can change a port or the share and paste again.

Why does it turn FastTrack off?

FastTracked packets skip the firewall mangle rules, so the connection marks that choose the WAN would never be applied and the balancing would silently stop. The script disables the FastTrack rule; your other filter rules are untouched.

What if my WAN gets its address by DHCP?

Choose DHCP for that line. The script adds a DHCP client that does not install a default route, reads the gateway from the lease and keeps the check-host route pointed at it whenever the lease changes.

Can I share the traffic unevenly?

Yes. Choose 2:1 or 3:1 in either direction. The share applies to new connections; each customer-to-server pair always stays on one line.

Read more

Where RadiusNest fits

Load balancing keeps the lines busy; RadiusNest keeps the customers paying. It is cloud billing for MikroTik ISPs and hotspot operators: packages with speed, data and time limits, vouchers, PPPoE and hotspot logins, resellers, payments, and this generator built in. One paste connects a router.

Start the free trial See pricing