MikroTik Failover with Dual WAN, Check-Gateway and Netwatch
Build a reliable dual-WAN failover on RouterOS 7 using distance-based routes, check-gateway and a Netwatch alert when the primary link drops.
Common Symptoms and Quick Fixes
| Symptom | Likely Cause | Quick Fix |
|---|---|---|
| No internet when WAN1 fails | Static route never goes inactive | Use check-gateway=ping or recursive routes |
| Failover works but never fails back | Route distance not set correctly | Primary must have the lower distance |
| Clients keep old connections | Connection tracking not cleared | Accept brief reconnect or add a Netwatch script |
Method 1: Distance-Based Failover
The primary WAN has the lower distance. If its gateway stops answering, the backup route takes over automatically. Replace the example gateways with your ISP gateways.
/ip route add dst-address=0.0.0.0/0 gateway=192.0.2.1 distance=1 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=198.51.100.1 distance=2
Pro Tip for Administratorscheck-gateway=ping only tests the next hop. For a real internet check use a recursive route (Method 2).
Method 2: Recursive Route to Test the Real Internet
Route a public IP through each gateway and make the default route depend on it.
/ip route add dst-address=1.1.1.1/32 gateway=192.0.2.1 scope=10
/ip route add dst-address=0.0.0.0/0 gateway=1.1.1.1 target-scope=11 distance=1 check-gateway=ping
/ip route add dst-address=0.0.0.0/0 gateway=198.51.100.1 distance=2
Method 3: Test and Log with Netwatch
Unplug WAN1 and confirm the route flips. Netwatch adds a log line you can use for alerts.
/ip route print where dst-address=0.0.0.0/0
/tool netwatch add host=1.1.1.1 interval=10s down-script=":log warning \"WAN1 DOWN\"" up-script=":log info \"WAN1 UP\""
Frequently Asked Questions (FAQ)
Q: Do I need Netwatch for failover?
No. Routing handles failover. Netwatch is only for logging, e-mail or custom actions.
Q: Do I need NAT for both WANs?
Yes. Add a masquerade rule for each WAN interface.