RadiusNest › Guides

MikroTik PPPoE client setup

Last updated: 2 October 2026

Many fibre and DSL lines need a PPPoE username and password. This guide sets up the PPPoE client on a MikroTik WAN port and fixes the usual "connected but some sites do not open" problem.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

1. Create the client

/interface pppoe-client add name=pppoe-out1 interface=ether1 user=YOUR-USER password=YOUR-PASSWORD add-default-route=yes use-peer-dns=yes disabled=no

If your ISP needs a VLAN, create the VLAN on ether1 first and put the client on the VLAN interface.

Example for an ISP that uses VLAN 10:

/interface vlan add name=vlan10-wan interface=ether1 vlan-id=10
/interface pppoe-client set pppoe-out1 interface=vlan10-wan

If the ISP gave you a modem, it must be in bridge mode so that your MikroTik makes the PPPoE connection. If the modem stays in router mode, it is already logged in and the MikroTik only needs a DHCP client on ether1.

2. NAT through the PPPoE interface

/ip firewall nat add chain=srcnat out-interface=pppoe-out1 action=masquerade

If you use interface lists, add pppoe-out1 to the WAN list so the default firewall protects it.

/interface list member add list=WAN interface=pppoe-out1

3. The MSS fix

PPPoE packets are slightly smaller than normal ones. Without this rule some websites hang:

/ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn out-interface=pppoe-out1 action=change-mss new-mss=clamp-to-pmtu passthrough=yes

4. Check

/interface pppoe-client monitor pppoe-out1 once
/ip route print where dst-address=0.0.0.0/0
/ping 8.8.8.8 count=4

Keep an eye on it

The interface shows R (running) when the session is up. The log records every disconnect with a reason, which is what your ISP will ask for:

/interface pppoe-client print
/log print where topics~"pppoe"

A PPPoE line works as either line of a two-line setup; see failover and use pppoe-out1 as the gateway.

If it does not connect

  • "authentication failed": username or password is wrong, or the line is locked to the old router's MAC address.
  • Stays on "connecting": wrong port, missing VLAN, or the cable or modem is not in bridge mode.
  • Connected, no browsing: NAT rule missing, or DNS not set.

Questions and answers

Do I still need a DHCP client on the WAN port?

No. With PPPoE the address comes through the PPPoE session. Remove a DHCP client on the same port to avoid confusion.

Why do some websites not open over PPPoE?

Packet size. Add the change-mss rule shown above.

How do I check that the ISP's PPPoE server answers?

Run /interface pppoe-client scan ether1 to list the PPPoE servers that answer on that port.

Related guides

Start the free trial See pricing