GRE tunnel on MikroTik router
IP addresses provided by Luxxy.cloud (example values):
Luxxy GRE server: 5.231.32.3 Luxxy local GRE server address: 100.65.0.1 Your local address: 100.65.0.2 Your public IPs: 5.231.32.101, 5.231.32.102, 5.231.32.103, 5.231.32.104 Note: These are example IP addresses. You will receive the correct IP addresses from Luxxy.cloud.
Local IP address of your MikroTik router (WAN interface): 192.168.1.201 Note: Your MikroTik WAN IP may be different.
1. Rename interfaces
/interface ethernet
set [find default-name=ether2] disable-running-check=no name=LAN
set [find default-name=ether1] disable-running-check=no name=WAN
2. Create GRE interface
/interface gre
add local-address=192.168.1.201 mtu=1476 name=GRE-luxxy remote-address=5.231.32.3
3. Add IP addresses
/ip address
add address=100.65.0.2/30 interface=GRE-luxxy network=100.65.0.0
add address=5.231.32.101 interface=LAN network=5.231.32.101
Public IP 5.231.32.101 is your “main address” in the allocated range. Remaining 5.231.32.102–104 will be assigned by DHCP to the servers.
4. Firewall (access to the public IP)
/ip firewall filter
add action=accept chain=input dst-address=5.231.32.101 protocol=icmp
add action=drop chain=input dst-address=5.231.32.101
Thesehese rules apply only to the public IP — the rest of the router remains accessible normally.
5. Create a separate routing table
/routing table
add disabled=no fib name=luxxy
6. Routing: GRE as the default path for public IPs
/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=100.65.0.1 \
routing-table=luxxy scope=30 suppress-hw-offload=no target-scope=10
add disabled=no dst-address=5.231.32.102/32 gateway=LAN routing-table=main
add disabled=no dst-address=5.231.32.103/32 gateway=LAN routing-table=main
add disabled=no dst-address=5.231.32.104/32 gateway=LAN routing-table=main
Servers on your LAN receiving public IPs will be ARP-visible on the LAN, therefore gateway=LAN is correct.
7. Routing rules — send traffic from public IPs via GRE
/routing rule
add action=lookup disabled=no src-address=5.231.32.102/32 table=luxxy
add action=lookup disabled=no src-address=5.231.32.103/32 table=luxxy
add action=lookup disabled=no src-address=5.231.32.104/32 table=luxxy
This ensures that servers with public IPs route their outbound traffic through the tunnel.
8. DHCP pool for public IPs
/ip pool
add name=POOL-luxxy ranges=5.231.32.102,5.231.32.103,5.231.32.104
9. Enable DHCP server
/ip dhcp-server
add address-pool=POOL-luxxy interface=LAN lease-time=2d name=DHCP-luxxy
10. DHCP network parameters
/ip dhcp-server network
add address=5.231.32.0/24 dns-server=1.1.1.1,8.8.8.8 gateway=5.231.32.101 netmask=24
✅ Done!
Your public IPs should now route through the GRE tunnel.