MikroTik policy-based routing: send chosen users through the second line
Last updated: 11 October 2026
Sometimes you do not want to balance at all: the office goes through the fibre, the guest Wi-Fi through the cheaper line, or one customer has paid for a line of their own. That is policy-based routing.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
In the examples line 2 has gateway 192.168.2.1 on ether2, and the device to move is 192.168.88.50.
1. A route for line 2
RouterOS v7 (a routing table, then a route in it):
/routing table add name=to_WAN2 fib
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN2 check-gateway=pingRouterOS v6:
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_WAN2 check-gateway=ping2a. By source address: a routing rule
The simplest way for a device or a whole network. v7:
/routing rule add dst-address=192.168.0.0/16 action=lookup table=main comment="local stays local"
/routing rule add src-address=192.168.88.50/32 action=lookup table=to_WAN2v6:
/ip route rule add dst-address=192.168.0.0/16 action=lookup table=main
/ip route rule add src-address=192.168.88.50/32 action=lookup table=to_WAN2The first rule keeps traffic between your own networks on the normal routes. Change 192.168.0.0/16 to cover all your local ranges. For a whole network use, for example, src-address=192.168.30.0/24.
action=lookup means: use this table, and if it has no working route, carry on with the normal one. When line 2 is down, check-gateway takes its route away and the device falls back to line 1. If the device must never use line 1, use action=lookup-only-in-table instead.
2b. By anything else: mangle
To choose by address list, port or destination, mark with mangle. For example, everyone in the list via-wan2:
/ip firewall address-list add list=via-wan2 address=192.168.88.50
/ip firewall address-list add list=via-wan2 address=192.168.88.51
/ip firewall mangle add chain=prerouting src-address-list=via-wan2 dst-address-type=!local action=mark-routing new-routing-mark=to_WAN2 passthrough=noMangle routing marks are skipped by FastTracked connections, so with this method turn FastTrack off or exclude these users from it. Routing rules (2a) do not have that problem.
3. NAT on line 2
/ip firewall nat add chain=srcnat out-interface=ether2 action=masqueradeCheck
From the device, open a "what is my IP" page: it should show line 2's address. On the router:
/routing rule print
/ip route print where routing-table=to_WAN2(On v6: /ip route rule print and /ip route print where routing-mark=to_WAN2.)
PPPoE customers
To send one PPPoE customer out of a dedicated line, give them a static address and use that address in the rule.
Questions and answers
How do I route one IP through WAN2 on MikroTik?
Make a routing table with a default route through WAN2, then a routing rule with src-address set to that IP and action=lookup to that table.
What is the difference between lookup and lookup-only-in-table?
lookup falls back to the main table when the chosen table has no working route; lookup-only-in-table does not, so the traffic is dropped instead.
Does policy-based routing work with FastTrack?
Routing rules do. Mangle routing marks do not see FastTracked connections, so turn FastTrack off for them.