If a simple queue does not limit a FastTracked client, add established/related accepts for that client before the first matching FastTrack rule. Use both directions. The same exclusion keeps a policy-routed client out of FastTrack’s main-table lookup.
Place established-flow exceptions before FastTrack
Run /ip/firewall/filter/print detail where chain=forward. Replace <fasttrack-rule-id> below with the first FastTrack rule the client can reach. The example client is 192.0.2.10; substitute yours. A rule placed after FastTrack will not fix the bypass.
/ip/firewall/filter
add chain=forward action=accept connection-state=established,related src-address=192.0.2.10 place-before=<fasttrack-rule-id> comment="example-client slow path outbound"
add chain=forward action=accept connection-state=established,related dst-address=192.0.2.10 place-before=<fasttrack-rule-id> comment="example-client slow path return"These exceptions do not permit new connections; retain the existing new-session policy. For policy routing, the same two-direction host exception applies to the client using the other table. Expand the address match to its subnet only if that whole subnet needs normal processing.
In /queue/simple/print detail, confirm target includes the client and max-limit is the expected rate; an unlimited queue remains unlimited after this fix. Check that an established accept does not skip a deliberate later restriction.
Scope: RouterOS IPv4 TCP/UDP software FastTrack. Hardware offload is covered in the model guide.
Retest with a new connection
Existing FastTracked connections may retain their state until they close or expire. Reconnect the test application instead of clearing the whole connection table. Keep Torch/sniffer stopped. For shaping, compare the application’s sustained rate with the queue’s max-limit and re-read /queue/simple/print stats. During the transfer run /system/resource/print and read cpu-load; excluding a busy flow can increase CPU use.
For policy routing, test a new connection with Torch/sniffer stopped. On a masqueraded connection, compare reply-dst-address in /ip/firewall/connection/print detail with the intended WAN address in /ip/address/print. If addresses are shared, use an external port mirror to check the actual exit without changing FastTrack behavior.
To undo the exception, remove only the two added rule IDs.