MikroTik Dual-Site Failover Setup
Budget: ₹1,500 – ₹12,500 INR
I have two offices, each running a MikroTik router. If the primary internet line at either location goes down, I want traffic to swing automatically to the other site’s link while all local services should share the local network for voip and nas, Also I need Softether setup for open vpn
Current network details
• Each office already has its own set of subnets and some tailored DHCP scopes.
• There are a few bespoke routing rules that let internal servers reach special resources, so those routes must stay intact after the switchover.
What I need from you
1. A clean, reproducible RouterOS configuration for both sites that:
– Establishes a reliable tunnel between the locations (IPsec, WireGuard or other MikroTik-native option you recommend).
– Detects WAN failure in under 30 seconds and redirects outbound traffic through the tunnel without user intervention.
– Preserves my multiple subnets and custom DHCP options on each side.
– Restores the original path automatically once the primary connection is healthy.
2. A brief step-by-step document explaining each step for futher trubeshoot:
– Any firewall or NAT rules you add or modify.
– How to adjust the setup if I change a subnet or add a new VLAN later.
3. Remote session time (screen share) to test failover in real-time so we can confirm phones, printers, and servers stay reachable.
Acceptance criteria
• Pings, RDP, and VoIP calls survive an intentional WAN disconnect.
• No routing loops or asymmetric paths appear in the logs.
• CPU and memory usage on both MikroTiks remain within normal limits after the tunnel is up.
If you’ve tackled automatic failover with custom address spaces before, let’s get this running smoothly.
A
Current network details
• Each office already has its own set of subnets and some tailored DHCP scopes.
• There are a few bespoke routing rules that let internal servers reach special resources, so those routes must stay intact after the switchover.
What I need from you
1. A clean, reproducible RouterOS configuration for both sites that:
– Establishes a reliable tunnel between the locations (IPsec, WireGuard or other MikroTik-native option you recommend).
– Detects WAN failure in under 30 seconds and redirects outbound traffic through the tunnel without user intervention.
– Preserves my multiple subnets and custom DHCP options on each side.
– Restores the original path automatically once the primary connection is healthy.
2. A brief step-by-step document explaining each step for futher trubeshoot:
– Any firewall or NAT rules you add or modify.
– How to adjust the setup if I change a subnet or add a new VLAN later.
3. Remote session time (screen share) to test failover in real-time so we can confirm phones, printers, and servers stay reachable.
Acceptance criteria
• Pings, RDP, and VoIP calls survive an intentional WAN disconnect.
• No routing loops or asymmetric paths appear in the logs.
• CPU and memory usage on both MikroTiks remain within normal limits after the tunnel is up.
If you’ve tackled automatic failover with custom address spaces before, let’s get this running smoothly.
A
Related categories:
Linux
Education
Asterisk PBX
Network Administration
Network Security
VPN
Firewall