RadiusNest › Guides

MikroTik policy-based routing: send chosen users through the second line

Last updated: 11 October 2026

Sometimes you do not want to balance at all: the office goes through the fibre, the guest Wi-Fi through the cheaper line, or one customer has paid for a line of their own. That is policy-based routing.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

In the examples line 2 has gateway 192.168.2.1 on ether2, and the device to move is 192.168.88.50.

1. A route for line 2

RouterOS v7 (a routing table, then a route in it):

/routing table add name=to_WAN2 fib
/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-table=to_WAN2 check-gateway=ping

RouterOS v6:

/ip route add dst-address=0.0.0.0/0 gateway=192.168.2.1 routing-mark=to_WAN2 check-gateway=ping

2a. By source address: a routing rule

The simplest way for a device or a whole network. v7:

/routing rule add dst-address=192.168.0.0/16 action=lookup table=main comment="local stays local"
/routing rule add src-address=192.168.88.50/32 action=lookup table=to_WAN2

v6:

/ip route rule add dst-address=192.168.0.0/16 action=lookup table=main
/ip route rule add src-address=192.168.88.50/32 action=lookup table=to_WAN2

The first rule keeps traffic between your own networks on the normal routes. Change 192.168.0.0/16 to cover all your local ranges. For a whole network use, for example, src-address=192.168.30.0/24.

action=lookup means: use this table, and if it has no working route, carry on with the normal one. When line 2 is down, check-gateway takes its route away and the device falls back to line 1. If the device must never use line 1, use action=lookup-only-in-table instead.

2b. By anything else: mangle

To choose by address list, port or destination, mark with mangle. For example, everyone in the list via-wan2:

/ip firewall address-list add list=via-wan2 address=192.168.88.50
/ip firewall address-list add list=via-wan2 address=192.168.88.51
/ip firewall mangle add chain=prerouting src-address-list=via-wan2 dst-address-type=!local action=mark-routing new-routing-mark=to_WAN2 passthrough=no

Mangle routing marks are skipped by FastTracked connections, so with this method turn FastTrack off or exclude these users from it. Routing rules (2a) do not have that problem.

3. NAT on line 2

/ip firewall nat add chain=srcnat out-interface=ether2 action=masquerade

Check

From the device, open a "what is my IP" page: it should show line 2's address. On the router:

/routing rule print
/ip route print where routing-table=to_WAN2

(On v6: /ip route rule print and /ip route print where routing-mark=to_WAN2.)

PPPoE customers

To send one PPPoE customer out of a dedicated line, give them a static address and use that address in the rule.

Questions and answers

How do I route one IP through WAN2 on MikroTik?

Make a routing table with a default route through WAN2, then a routing rule with src-address set to that IP and action=lookup to that table.

What is the difference between lookup and lookup-only-in-table?

lookup falls back to the main table when the chosen table has no working route; lookup-only-in-table does not, so the traffic is dropped instead.

Does policy-based routing work with FastTrack?

Routing rules do. Mangle routing marks do not see FastTracked connections, so turn FastTrack off for them.

Related guides

Start the free trial See pricing