Mikrotik linked to another router via WAN

Hi all,

I am having a bit of trouble trying to setup this scenario.

BT Cisco router a on site Managed by BT and a pain to get any changes done (Has to remain and cannot be changed)
I would like to use the the Mikrotik behind the BT Cisco so if we need to make any changes we do not have to rely on BT (The ISP) to do the changes as they are very slow at doing anything.

The problem I am having is. The different networks I have setup are giving out the correct gateway but also giving out the gateway from the BT Cisco. Can you see what I have done wrong and any other pointers would be greatly appreciated :slight_smile:.

Here is an export of what i have done so far.

Thank you
Jonathan

# 2023-11-13 13:31:26 by RouterOS 7.12
# software id = YQ4C-98RZ
#
# model = CCR2004-16G-2S+
# serial number = <removed>
/interface bridge
add ingress-filtering=no name=LAN-bridge vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment=WAN-01 l2mtu=1592 mac-address=\
    18:FD:74:DD:A5:C6
set [ find default-name=ether2 ] comment=WAN-02 l2mtu=1592 mac-address=\
    18:FD:74:DD:A5:C7
set [ find default-name=ether3 ] comment="Uplink to Switch" l2mtu=1592 \
    mac-address=18:FD:74:DD:A5:C8
set [ find default-name=ether4 ] l2mtu=1592 mac-address=18:FD:74:DD:A5:C9
set [ find default-name=ether5 ] l2mtu=1592 mac-address=18:FD:74:DD:A5:CA
set [ find default-name=ether6 ] l2mtu=1592 mac-address=18:FD:74:DD:A5:CB
set [ find default-name=ether7 ] disabled=yes l2mtu=1592 mac-address=\
    18:FD:74:DD:A5:CC
set [ find default-name=ether8 ] disabled=yes l2mtu=1592 mac-address=\
    18:FD:74:DD:A5:CD
set [ find default-name=ether9 ] disabled=yes
set [ find default-name=ether10 ] disabled=yes
set [ find default-name=ether11 ] disabled=yes
set [ find default-name=ether12 ] disabled=yes
set [ find default-name=ether13 ] disabled=yes
set [ find default-name=ether14 ] disabled=yes
set [ find default-name=ether15 ] disabled=yes
set [ find default-name=ether16 ] disabled=yes
set [ find default-name=sfp-sfpplus2 ] disabled=yes name=ether17
set [ find default-name=sfp-sfpplus1 ] disabled=yes name=ether18
/interface vlan
add interface=LAN-bridge name=vlan10-OFFICE vlan-id=10
add interface=LAN-bridge name=vlan20-EPOS vlan-id=20
add interface=LAN-bridge name=vlan30-GUESTS vlan-id=30
/interface list
add name=LAN
add name=WAN1
add name=WAN2
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=ADMIN_dhcp ranges=10.0.0.20-10.0.0.254
add name=EPOS_dhcp ranges=10.0.20.2-10.0.20.254
add name=GUEST_dhcp ranges=10.0.30.2-10.0.30.254
add name=OFFICE_dchp ranges=10.0.10.2-10.0.10.254
/ip dhcp-server
add address-pool=ADMIN_dhcp interface=LAN-bridge lease-time=10m name=DHCP-ADMIN
add address-pool=EPOS_dhcp interface=vlan20-EPOS lease-time=10m name=DHCP-EPOS
add address-pool=GUEST_dhcp interface=vlan30-GUESTS lease-time=10m name=\
    DHCP-GUESTS
add address-pool=OFFICE_dchp interface=vlan10-OFFICE lease-time=10m name=\
    DHCP-OFFICE
/port
set 0 name=serial0
set 1 name=serial1
/queue simple
add burst-time=5s/5s comment="Bandwidth Guest Access" max-limit=20M/50M name=\
    GUEST-Q target=vlan30-GUESTS
/routing bgp template
set default disabled=no output.network=bgp-networks
/routing ospf instance
add disabled=no name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/system logging action
set 1 disk-file-name=flash/log
/interface bridge port
add bridge=LAN-bridge comment="Uplink to Switch" interface=ether3
add bridge=LAN-bridge interface=ether4
add bridge=LAN-bridge interface=ether5
add bridge=LAN-bridge interface=ether6
add bridge=LAN-bridge interface=ether7
add bridge=LAN-bridge interface=ether8
add bridge=LAN-bridge interface=ether9
add bridge=LAN-bridge interface=ether10
add bridge=LAN-bridge interface=ether11
add bridge=LAN-bridge interface=ether12
add bridge=LAN-bridge interface=ether13
add bridge=LAN-bridge interface=ether14
add bridge=LAN-bridge interface=ether15
add bridge=LAN-bridge interface=ether16
add bridge=LAN-bridge interface=ether17
add bridge=LAN-bridge interface=ether18
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface bridge vlan
add bridge=LAN-bridge comment=vlan20-EPOS tagged=\
    LAN-bridge,ether3,ether4,ether5,*31 vlan-ids=20
add bridge=LAN-bridge comment=vlan30-GUESTS tagged=\
    LAN-bridge,ether3,ether4,ether5,*31 vlan-ids=30
add bridge=LAN-bridge comment=vlan10-OFFICE tagged=\
    LAN-bridge,ether3,ether4,ether5,*31 vlan-ids=10
/interface list member
add interface=LAN-bridge list=LAN
add interface=ether1 list=WAN1
add interface=ether2 list=WAN2
/interface ovpn-server server
set auth=sha1,md5
/ip address
add address=10.0.0.1/24 comment="ADMIN Network" interface=LAN-bridge network=\
    10.0.0.0
add address=10.0.20.1/24 comment="EPOS Network" interface=vlan20-EPOS network=\
    10.0.20.0
add address=10.0.30.1/24 comment="GUEST Network" interface=vlan30-GUESTS \
    network=10.0.30.0
add address=10.0.10.1/24 comment="OFFICE Network" interface=vlan10-OFFICE \
    network=10.0.10.0
/ip dhcp-client
add comment="WAN 1 (ether 1) DCHP Client" default-route-distance=5 interface=\
    ether1
add comment="WAN 2 (ether 2) DCHP Client" default-route-distance=5 interface=\
    ether2
/ip dhcp-server network
add address=10.0.0.0/24 comment="Admin Network" dns-server=8.8.8.8,1.1.1.1 \
    gateway=10.0.0.1 netmask=24
add address=10.0.10.0/24 comment="Office Network (vlan10)" dns-server=\
    8.8.8.8,1.1.1.1 gateway=10.0.10.1 netmask=24
add address=10.0.20.0/24 comment="EPOS Network (vlan20)" dns-server=\
    8.8.8.8,1.1.1.1 gateway=10.0.20.1
add address=10.0.30.0/24 comment="Guest Network (vlan30)" dns-server=\
    8.8.8.8,1.1.1.1 gateway=10.0.30.1
/ip firewall filter
add action=accept chain=input comment=\
    "Accept established and related connections" connection-state=\
    established,related
add action=accept chain=input comment="Accept ICMP" protocol=icmp
add action=accept chain=input comment="Accept DNS" dst-port=53 protocol=udp
add action=accept chain=input comment="Accept DHCP" dst-port=67,68 protocol=udp
add action=drop chain=input comment="Drop all other input traffic" disabled=yes \
    log=yes
/ip firewall mangle
add action=accept chain=prerouting src-address=10.0.0.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment=WAN1 out-interface=ether1
add action=masquerade chain=srcnat comment=WAN2 out-interface=ether2
/ip smb shares
set [ find default=yes ] directory=/flash/pub
/routing bfd configuration
add disabled=no interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/system clock
set time-zone-name=Europe/London
/system identity
set name=Kingswood
/system leds
set 0 leds="" type=interface-activity
set 1 leds=""
set 2 leds="" type=interface-activity
set 3 leds=""
set 4 interface=ether4 leds="" type=interface-activity
add interface=ether5 leds="" type=interface-activity
add interface=ether6 leds="" type=interface-activity
add interface=ether7 leds="" type=interface-activity
add interface=ether8 leds="" type=interface-activity
add interface=*A leds="" type=interface-activity
add interface=*B leds="" type=interface-activity
add interface=*C leds="" type=interface-activity
add interface=*D leds="" type=interface-activity
add interface=*E leds="" type=interface-activity
add interface=*F leds="" type=interface-activity
add interface=*10 leds="" type=interface-activity
add interface=*11 leds="" type=interface-activity
add interface=*12 leds="" type=interface-activity
add interface=*13 leds="" type=interface-activity
add interface=*14 leds="" type=interface-activity
add interface=*15 leds="" type=interface-activity
add interface=*16 leds="" type=interface-activity
add interface=*17 leds="" type=interface-activity
add interface=*18 leds="" type=interface-activity
add interface=*19 leds="" type=interface-activity
add interface=*19 leds="" type=interface-speed
add interface=*1A leds="" type=interface-activity
add interface=*1A leds="" type=interface-speed
/system note
set show-at-login=no
/system resource irq rps
set *1 disabled=yes
set *A disabled=yes
set *B disabled=yes
set *C disabled=yes
set *D disabled=yes
set *E disabled=yes
set *F disabled=yes
set *10 disabled=yes
set *11 disabled=yes
set *12 disabled=yes
set *13 disabled=yes
set *14 disabled=yes
set *15 disabled=yes
set *16 disabled=yes
set *17 disabled=yes
set *18 disabled=yes
set *19 disabled=yes
set *1A disabled=yes
/system routerboard settings
set enter-setup-on=delete-key
/tool romon
set enabled=yes

DHCP can only hand out a single default gateway (it can also hand out a routing table but still just a single gateway per destination prefix, and there is nothing related to this in your config). Since your /ip dhcp-server network items look fine to me, could it be that the devices have the route via the BT gear gateway configured statically somewhere? How does the routing table of an affected device look like?

Thank you, I think it was the PC I as using to configure it was having a wobble. Since rebooting it everything seems to be behaving itself.
Thank you for taking a look. I am pretty new to Mikrotik, Does everything else look OK?