How to configure multiprofile on Mikrotik
Overview
Through the creation of firewall rules, multiple browsing profiles can be used on the same network. In this way, two or more machines connected to the same network will be able to use different filtering rules and you can more easily split data traffic. For additional information on multiprofile configurations, please refer to our main platform documentation.
This guide is only usable in standard workgroup environments, meaning setups without Active Directory servers.
Variables to Replace
The following commands allow you to create rules to manage up to five browsing profiles. However, it is not mandatory to use all of them. Depending on your needs, it will be sufficient to delete the superfluous parts of the code.
Before running the commands on your MikroTik terminal, you must edit the following placeholder fields with your actual data:
- List_IP1 to List_IP4: The list of IP addresses that will be assigned to each specific profile. You can enter a single IP or a range of IPs using the hyphen symbol between the first and last IP in the range, like 192.168.1.2-192.168.1.100.
- Profile1 to Profile4: The custom name assigned to each profile, if applicable.
Terminal Configuration
Open a New Terminal window in WinBox and execute the following customized commands:
/ip firewall address-list
add address=<List_IP1> list=<Profile1>
add address=<List_IP2> list=<Profile2>
add address=<List_IP3> list=<Profile3>
add address=<List_IP4> list=<Profile4>
/ip firewall nat
# <Profile1>
add action=dst-nat chain=dstnat comment=<Profile1> dst-port=53 protocol=udp \
src-address-list=<Profile1> to-addresses=185.236.104.114 to-ports=53
add action=dst-nat chain=dstnat comment=<Profile1> dst-port=53 protocol=tcp \
src-address-list=<Profile1> to-addresses=185.236.104.114 to-ports=53
# <Profile2>
add action=dst-nat chain=dstnat comment=<Profile2> dst-port=53 protocol=udp \
src-address-list=<Profile2> to-addresses=185.236.104.124 to-ports=53
add action=dst-nat chain=dstnat comment=<Profile2> dst-port=53 protocol=tcp \
src-address-list=<Profile2> to-addresses=185.236.104.124 to-ports=53
# <Profile3>
add action=dst-nat chain=dstnat comment=<Profile3> dst-port=53 protocol=udp \
src-address-list=<Profile3> to-addresses=185.236.104.134 to-ports=53
add action=dst-nat chain=dstnat comment=<Profile3> dst-port=53 protocol=tcp \
src-address-list=<Profile3> to-addresses=185.236.104.134 to-ports=53
# <Profile4>
add action=dst-nat chain=dstnat comment=<Profile4> dst-port=53 protocol=udp \
src-address-list=<Profile4> to-addresses=185.236.104.144 to-ports=53
add action=dst-nat chain=dstnat comment=<Profile4> dst-port=53 protocol=tcp \
src-address-list=<Profile4> to-addresses=185.236.104.144 to-ports=53
# Default Profile
add action=dst-nat chain=dstnat comment=Default dst-port=53 protocol=udp \
to-addresses=185.236.104.104 to-ports=53
add action=dst-nat chain=dstnat comment=Default dst-port=53 protocol=tcp \
to-addresses=185.236.104.104 to-ports=53The Default profile rule routing to 104.104 must always have a lower priority than your other specific profile rules inside your firewall table.