Use the symptom below to open the matching RouterOS fix. A router that can reach the Internet while its clients cannot usually needs a LAN forwarding, NAT or DNS correction; repeatedly pinging from the router will not locate that client-side failure.
Choose the problem you are seeing
- DNS works on the router but not on clients: allow LAN DNS requests and correct the client resolver.
- A port forward works externally but fails from the LAN: add the matching hairpin NAT path.
- VLAN filtering removed management access: restore the management VLAN’s bridge/CPU membership.
- Queues or policy routing stop working with FastTrack: exclude the affected connections before FastTrack.
- WireGuard has a handshake but no LAN traffic: correct the peer prefixes, routes or forward rule.
- LTE registers but has no Internet: check the active APN and the MBIM network-APN override.
- A tool reports
failure: not allowed by device-mode: enable that feature and complete physical confirmation.
A short path test
Here 10.42.50.20 is a sample LAN host. Replace it with the failing destination when checking a routed path.
/ping 10.42.50.20 count=5/tool/traceroute 10.42.50.20Stop traceroute with Ctrl+C once you have the path sample. An unanswered hop may suppress ICMP rather than drop forwarded traffic; do not diagnose a fault from one asterisk. Then test DNS separately:
:put [:resolve "pjhtech.com"]For a client DNS failure, also query from that client; its resolver and firewall path can differ from the router’s.