MikroTik mangle explained: connection, packet and routing marks
Last updated: 11 October 2026
Mangle does not block or allow anything. It puts labels (marks) on connections and packets so that other parts of the router can treat them differently: queues limit marked packets, routes send marked traffic out of a chosen line. Almost every load-balancing and traffic-shaping guide uses it.
The three marks
| Mark | Sits on | Used by |
|---|---|---|
mark-connection | The whole connection, both directions, for its lifetime | Other mangle rules, to mark its packets cheaply |
mark-packet | One packet | Queues (queue tree, simple queue packet-marks) |
mark-routing | One packet | Routes: the packet uses the routing table (v7) or routes with that mark (v6) |
The usual pattern: mark the connection once, on its first packet, and then mark packets or routes by checking the connection mark. Matching complex conditions on every packet costs CPU; checking a mark costs almost nothing.
A worked example
/ip firewall mangle
add chain=forward src-address=192.168.88.50 connection-mark=no-mark action=mark-connection new-connection-mark=cam_conn passthrough=yes
add chain=forward connection-mark=cam_conn action=mark-packet new-packet-mark=cam_pkt passthrough=noThe first rule labels new connections from a camera recorder. The second labels every packet of those connections, both ways, so a queue can limit them:
/queue simple add name=camera target=192.168.88.0/24 packet-marks=cam_pkt max-limit=2M/2MChains: where the rule looks
- prerouting: every packet coming in, before the routing decision. Routing marks for traffic from your LAN go here.
- output: packets the router itself sends. Routing marks for the router's own connections go here.
- forward: packets passing through the router. Good for marks used by queues.
- input and postrouting: traffic to the router, and everything leaving it.
passthrough
With passthrough=yes the packet goes on to the next mangle rule after this one acts; with no, mangle stops there for that packet. Mark connections with yes (so the next rule can mark the packet), and make the final packet or routing mark rule no.
change-mss
Mangle also changes things in packets. The common case lowers the TCP segment size on PPPoE and tunnels so that large pages do not stall:
/ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn out-interface=pppoe-out1 action=change-mss new-mss=clamp-to-pmtu passthrough=yesSee PPPoE MTU and MSS.
Routing marks on v7
On RouterOS v7 a routing mark must name a routing table that exists, created with /routing table add name=to_WAN2 fib. Make the table first, then the rule.
Why mangle "stops working"
FastTrack sends established connections past the firewall, mangle included. Marked queues and routes then work for the first packets only. Turn FastTrack off, or exclude marked connections from it:
/ip firewall filter set [find action=fasttrack-connection] connection-mark=no-markMore on this: speed limit not working.
See what your rules catch
/ip firewall mangle print stats
/ip firewall connection print where connection-mark=cam_connA rule whose counters stay at zero is never reached: an earlier rule with passthrough=no took the packet, or its conditions do not match.
Questions and answers
What is the difference between mark-connection and mark-packet?
A connection mark stays on the whole connection; a packet mark is on one packet and is what queues look at. Mark the connection first, then mark its packets.
Does mangle block traffic?
No. Mangle only marks or changes packets. Blocking is done in the filter rules.
Why do my mangle counters stay at zero?
FastTrack, an earlier rule with passthrough=no, or conditions that never match, such as the wrong interface.