MikroTik troubleshooting tools: ping, traceroute, torch and more
Last updated: 11 October 2026
When a customer says "the internet is not working", RouterOS has the tools to find out where it stops. These are the commands worth knowing by heart, in the order you usually need them.
Ping: can I reach it?
/ping 8.8.8.8 count=5
/ping 8.8.8.8 count=5 interface=pppoe-out2
/ping 8.8.8.8 count=5 src-address=192.168.88.1Pinging from a chosen line or address tests each line separately and checks that the return path to your LAN works. interface= is reliable on PPPoE and other point-to-point lines; on an Ethernet line it treats the target as directly connected and usually times out. There, on v7, ping through that line's routing table instead: /ping 8.8.8.8 routing-table=to_WAN2 (see PCC for the tables).
Ping with size: the MTU test
/ping 8.8.8.8 size=1472 do-not-fragment count=3Lower the size until replies come back. On PPPoE the largest working size is usually 1464; this is the number behind MTU and MSS problems.
Traceroute: where does it stop?
/tool traceroute 8.8.8.8Each line is one router on the way. The first hop with no answer and no later answers shows where traffic stops. Some routers on the internet never answer traceroute, so a single silent hop in the middle means nothing.
DNS: is it names or the connection?
:put [:resolve google.com]Ping by address works but by name fails: a DNS problem; see DNS setup.
Link: is the cable or port the problem?
/interface ethernet monitor ether1 once
/interface print stats where name=ether1The monitor shows the negotiated speed: 100 Mbit/s on a gigabit cable usually means a damaged cable or connector. Growing error counts in the stats point the same way.
Torch: who is using the line right now?
/tool torch interface=ether1 src-address=0.0.0.0/0 dst-address=0.0.0.0/0Live traffic per address. More in see who is using the bandwidth.
Interface traffic over time
/interface monitor-traffic ether1Sniffer: what exactly is on the wire?
/tool sniffer quick interface=ether1 ip-address=192.168.88.50A live list of packets to and from one device: whether a request goes out and an answer comes back. For a full capture, save to a file and open it in Wireshark:
/tool sniffer set file-name=capture.pcap filter-ip-address=192.168.88.50
/tool sniffer start
/tool sniffer stopARP and DHCP: is the device there?
/ip arp print where address=192.168.88.50
/ip dhcp-server lease print where address=192.168.88.50The log, live
/log print followLeave it running while the customer tries again. Press Q to stop.
Is the router itself the bottleneck?
/system resource print
/tool profile duration=10sSee MikroTik at 100% CPU, and test real line speed with bandwidth test.
The usual order
- Ping the router's own LAN address from the customer side, then the gateway, then the internet by address.
- Resolve a name.
- Traceroute where pings stop.
- Look at the link and the log.
- Sniff only when the rest has not told you.
Questions and answers
How do I ping from a specific WAN on MikroTik?
On a PPPoE line, /ping with interface=pppoe-out1. On an Ethernet line, use src-address set to that line's address, or on v7 routing-table set to that line's table.
How do I capture packets on MikroTik for Wireshark?
Set /tool sniffer with a file-name and a filter, start it, stop it, then download the .pcap file from Files.
What does a timeout in MikroTik traceroute mean?
That hop did not answer. If later hops answer, it is just a router that ignores traceroute; if nothing after it answers, traffic stops there.