pjhtech Tools
MikroTik

MikroTik FastTrack Bypasses Queues or Policy Routing

Diagnose simple queues that do not limit traffic, missing packet marks and connections taking the wrong WAN when FastTrack is enabled.

If a simple queue does not limit a FastTracked client, add established/related accepts for that client before the first matching FastTrack rule. Use both directions. The same exclusion keeps a policy-routed client out of FastTrack’s main-table lookup.

Place established-flow exceptions before FastTrack

Run /ip/firewall/filter/print detail where chain=forward. Replace <fasttrack-rule-id> below with the first FastTrack rule the client can reach. The example client is 192.0.2.10; substitute yours. A rule placed after FastTrack will not fix the bypass.

Configuration change • placeholder rule ID must be replaced
/ip/firewall/filter
add chain=forward action=accept connection-state=established,related src-address=192.0.2.10 place-before=<fasttrack-rule-id> comment="example-client slow path outbound"
add chain=forward action=accept connection-state=established,related dst-address=192.0.2.10 place-before=<fasttrack-rule-id> comment="example-client slow path return"

These exceptions do not permit new connections; retain the existing new-session policy. For policy routing, the same two-direction host exception applies to the client using the other table. Expand the address match to its subnet only if that whole subnet needs normal processing.

In /queue/simple/print detail, confirm target includes the client and max-limit is the expected rate; an unlimited queue remains unlimited after this fix. Check that an established accept does not skip a deliberate later restriction.

Scope: RouterOS IPv4 TCP/UDP software FastTrack. Hardware offload is covered in the model guide.

Retest with a new connection

Existing FastTracked connections may retain their state until they close or expire. Reconnect the test application instead of clearing the whole connection table. Keep Torch/sniffer stopped. For shaping, compare the application’s sustained rate with the queue’s max-limit and re-read /queue/simple/print stats. During the transfer run /system/resource/print and read cpu-load; excluding a busy flow can increase CPU use.

For policy routing, test a new connection with Torch/sniffer stopped. On a masqueraded connection, compare reply-dst-address in /ip/firewall/connection/print detail with the intended WAN address in /ip/address/print. If addresses are shared, use an external port mirror to check the actual exit without changing FastTrack behavior.

To undo the exception, remove only the two added rule IDs.

References