MikroTik load balancing and failover generator
Enter your WAN links and get RouterOS v7 PCC load balancing with recursive-route failover, or failover alone, with every block explained.
Runs in your browser; nothing you type leaves your device
Lock-out risk. Changing routes on a remote router can cut you off. Test in a lab, or turn on Safe Mode (Ctrl+X in the terminal) first.
Generates RouterOS v7 syntax (routing tables with fib, routing-table on routes). IPv4 only. WANs whose gateway changes over DHCP need their gateway updated by hand or by a DHCP client script. MikroTik and RouterOS are trademarks of SIA Mikrotīkls. This tool is independent and not affiliated with or endorsed by MikroTik.
How to set up PCC load balancing on MikroTik
- Choose PCC load balancing with failover, or failover only.
- Add each WAN with its interface, gateway (or the interface name for PPPoE and LTE), a public check host that answers ping, and a weight for its share of connections.
- List the local networks and the LAN interface list, turn off add-default-route on the WAN clients, and apply the script with Safe Mode on.
How the generated setup works
PCC load balancing has three moving parts. Mangle marks each new connection from the LAN with a connection mark chosen by the per-connection classifier, and marks connections that arrive on a WAN with that WAN, so replies to port forwards leave the way they came in. A second set of mangle rules turns each connection mark into a routing mark on every packet. Routing tables, one per WAN, then hold a default route through that WAN, with the other WANs at a higher distance as backups.
Failover uses recursive routes. A host route sends one public check host through each WAN only. The default routes use the check host as their gateway with target-scope=11, so RouterOS resolves it through that host route, and check-gateway=ping pings the check host every ten seconds. Two missed replies take the route down, and the next distance takes over; when the host answers again, the route comes back.
Before you apply it
- Set
add-default-route=noon the WAN DHCP or PPPoE clients, or their own default routes will win. - Upgrading an old v6 PCC setup? Run its export through the v6 to v7 migration helper to see what changes.
- Keep the firewall's input and forward chains in place; the firewall generator uses interface lists, so add every WAN to the WAN list.
Questions
How does PCC split traffic?
per-connection-classifier hashes fields of each new connection (both addresses, or addresses and ports) into N buckets, and each WAN takes some of the buckets. The connection keeps its mark, so all its packets use the same WAN. A weight of 2 gives a WAN two buckets, twice the share of a WAN with weight 1. The split is per connection, not per byte, so one big download still uses one link.
What is recursive failover and why use it?
check-gateway=ping on a normal default route only tests the ISP's first hop, which often stays up while the ISP's network behind it is broken. Here each WAN gets a host route to a public check host, and the default routes point at that host instead of the gateway. When the host stops answering over that WAN, RouterOS deactivates the routes through it and traffic moves to the next WAN.
Why are there output drop rules for the check hosts?
If a WAN's link goes down, its host route disappears and the router would reach the check host through another WAN instead, so the dead WAN would look healthy. The drop rules stop pings to each check host from leaving through any interface except its own WAN.
Do I need to disable FastTrack?
For PCC, yes. Routing marks are applied by mangle on every packet, and fasttracked packets skip mangle, so they would follow the main table instead of their WAN. Plain failover works with FastTrack on.
What changed from RouterOS v6 PCC guides?
v6 routes used routing-mark=, and marks were created implicitly. In v7 each mark must be a routing table created under /routing table with fib, and routes refer to it with routing-table=. Mangle still uses new-routing-mark. The v6 to v7 migration helper converts old routes and adds the tables.
Is anything I type sent anywhere?
No. The script is generated in your browser.