MikroTik ISP Router Configuration
Budget: $30 – $250 USD
I have a MikroTik running RouterOS that I want to turn into a mini-ISP edge. The box will sit behind several uplinks—one of them is a Starlink terminal and I may add fibre, DSL or cable later—so the configuration must bond or load-balance multiple connections and fail over cleanly.
Downstream, each customer plugs in their own router and receives an address via my DHCP pool. I need to be able to set a per-Mbps cap for every client, enforce a sensible firewall policy, and keep management, customer traffic and any future VoIP on separate VLANs.
Key elements I expect from you:
• Multi-WAN bonding / load balancing that includes Starlink
• Fully functional DHCP server handing out the ranges I specify
• Bandwidth control per user (simple queues or queue trees—your call)
• Robust firewall rules for basic security and DDoS protection
• VLAN scheme that isolates management and customer networks
Deliverables
1. An import-ready .rsc (or step-by-step CLI script) covering the entire configuration
2. A concise guide explaining how to add or remove uplinks, create new speed profiles, and expand VLANs
3. A live remote session to load the config, test throughput, verify fail-over and confirm firewall rule hits
Please rely only on standard RouterOS features (WinBox or pure CLI is fine). Once your setup lets me plug in a customer router, assign their speed, and watch traffic switch seamlessly between bonded links when one line drops, the job is complete.
Downstream, each customer plugs in their own router and receives an address via my DHCP pool. I need to be able to set a per-Mbps cap for every client, enforce a sensible firewall policy, and keep management, customer traffic and any future VoIP on separate VLANs.
Key elements I expect from you:
• Multi-WAN bonding / load balancing that includes Starlink
• Fully functional DHCP server handing out the ranges I specify
• Bandwidth control per user (simple queues or queue trees—your call)
• Robust firewall rules for basic security and DDoS protection
• VLAN scheme that isolates management and customer networks
Deliverables
1. An import-ready .rsc (or step-by-step CLI script) covering the entire configuration
2. A concise guide explaining how to add or remove uplinks, create new speed profiles, and expand VLANs
3. A live remote session to load the config, test throughput, verify fail-over and confirm firewall rule hits
Please rely only on standard RouterOS features (WinBox or pure CLI is fine). Once your setup lets me plug in a customer router, assign their speed, and watch traffic switch seamlessly between bonded links when one line drops, the job is complete.
Related categories:
System Admin
Linux
Cisco
Network Administration
Network Security
Firewall
Network Monitoring