Skip to main content

GRE tunnel on MikroTik router

IP addresses provided by Luxxy.cloud (example values):

Luxxy GRE server: 5.231.32.3 Luxxy local GRE server address: 100.65.0.1 Your local address: 100.65.0.2 Your public IPs: 5.231.32.101, 5.231.32.102, 5.231.32.103, 5.231.32.104 Note: These are example IP addresses. You will receive the correct IP addresses from Luxxy.cloud.

Local IP address of your MikroTik router (WAN interface): 192.168.1.201 Note: Your MikroTik WAN IP may be different.

  1. Rename interfaces
/interface ethernet
set [find default-name=ether2] disable-running-check=no name=LAN
set [find default-name=ether1] disable-running-check=no name=WAN
  1. Create GRE interface

/interface gre
add local-address=192.168.1.201 mtu=1476 name=GRE-luxxy remote-address=5.231.32.3

  1. Add IP addresses

/ip address
add address=100.65.0.2/30 interface=GRE-luxxy network=100.65.0.0
add address=5.231.32.101 interface=LAN network=5.231.32.101

Public IP 5.231.32.101 is your “main address” in the allocated range. Remaining 5.231.32.102–104 will be assigned by DHCP to the servers.

  1. Firewall (access to the public IP)
/ip firewall filter
add action=accept chain=input dst-address=5.231.32.101 protocol=icmp
add action=drop chain=input dst-address=5.231.32.101

These rules apply only to the public IP — the rest of the router remains accessible normally.

  1. Create a separate routing table

/routing table
add disabled=no fib name=luxxy

  1. Routing: GRE as the default path for public IPs

/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=100.65.0.1 
\ routing-table=luxxy scope=30 suppress-hw-offload=no target-scope=10

add disabled=no dst-address=5.231.32.102/32 gateway=LAN routing-table=main add disabled=no dst-address=5.231.32.103/32 gateway=LAN routing-table=main add disabled=no dst-address=5.231.32.104/32 gateway=LAN routing-table=main

Servers on your LAN receiving public IPs will be ARP-visible on the LAN, therefore gateway=LAN is correct.

  1. Routing rules — send traffic from public IPs via GRE
/routing rule
add action=lookup disabled=no src-address=5.231.32.102/32 table=luxxy
add action=lookup disabled=no src-address=5.231.32.103/32 table=luxxy
add action=lookup disabled=no src-address=5.231.32.104/32 table=luxxy

This ensures that servers with public IPs route their outbound traffic through the tunnel.

  1. DHCP pool for public IPs

/ip pool
add name=POOL-luxxy ranges=5.231.32.102,5.231.32.103,5.231.32.104

  1. Enable DHCP server

/ip dhcp-server
add address-pool=POOL-luxxy interface=LAN lease-time=2d name=DHCP-luxxy

  1. DHCP network parameters

/ip dhcp-server network
add address=5.231.32.0/24 dns-server=1.1.1.1,8.8.8.8 gateway=5.231.32.101 netmask=24