RadiusNest › Guides

MikroTik mangle explained: connection, packet and routing marks

Last updated: 11 October 2026

Mangle does not block or allow anything. It puts labels (marks) on connections and packets so that other parts of the router can treat them differently: queues limit marked packets, routes send marked traffic out of a chosen line. Almost every load-balancing and traffic-shaping guide uses it.

The three marks

MarkSits onUsed by
mark-connectionThe whole connection, both directions, for its lifetimeOther mangle rules, to mark its packets cheaply
mark-packetOne packetQueues (queue tree, simple queue packet-marks)
mark-routingOne packetRoutes: the packet uses the routing table (v7) or routes with that mark (v6)

The usual pattern: mark the connection once, on its first packet, and then mark packets or routes by checking the connection mark. Matching complex conditions on every packet costs CPU; checking a mark costs almost nothing.

A worked example

/ip firewall mangle
add chain=forward src-address=192.168.88.50 connection-mark=no-mark action=mark-connection new-connection-mark=cam_conn passthrough=yes
add chain=forward connection-mark=cam_conn action=mark-packet new-packet-mark=cam_pkt passthrough=no

The first rule labels new connections from a camera recorder. The second labels every packet of those connections, both ways, so a queue can limit them:

/queue simple add name=camera target=192.168.88.0/24 packet-marks=cam_pkt max-limit=2M/2M

Chains: where the rule looks

  • prerouting: every packet coming in, before the routing decision. Routing marks for traffic from your LAN go here.
  • output: packets the router itself sends. Routing marks for the router's own connections go here.
  • forward: packets passing through the router. Good for marks used by queues.
  • input and postrouting: traffic to the router, and everything leaving it.

passthrough

With passthrough=yes the packet goes on to the next mangle rule after this one acts; with no, mangle stops there for that packet. Mark connections with yes (so the next rule can mark the packet), and make the final packet or routing mark rule no.

change-mss

Mangle also changes things in packets. The common case lowers the TCP segment size on PPPoE and tunnels so that large pages do not stall:

/ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn out-interface=pppoe-out1 action=change-mss new-mss=clamp-to-pmtu passthrough=yes

See PPPoE MTU and MSS.

Routing marks on v7

On RouterOS v7 a routing mark must name a routing table that exists, created with /routing table add name=to_WAN2 fib. Make the table first, then the rule.

Why mangle "stops working"

FastTrack sends established connections past the firewall, mangle included. Marked queues and routes then work for the first packets only. Turn FastTrack off, or exclude marked connections from it:

/ip firewall filter set [find action=fasttrack-connection] connection-mark=no-mark

More on this: speed limit not working.

See what your rules catch

/ip firewall mangle print stats
/ip firewall connection print where connection-mark=cam_conn

A rule whose counters stay at zero is never reached: an earlier rule with passthrough=no took the packet, or its conditions do not match.

Questions and answers

What is the difference between mark-connection and mark-packet?

A connection mark stays on the whole connection; a packet mark is on one packet and is what queues look at. Mark the connection first, then mark its packets.

Does mangle block traffic?

No. Mangle only marks or changes packets. Blocking is done in the filter rules.

Why do my mangle counters stay at zero?

FastTrack, an earlier rule with passthrough=no, or conditions that never match, such as the wrong interface.

Related guides

Start the free trial See pricing