Routing Netflix traffic of a LAN client via a wireguard

In this example, we will route Netflix traffic from a specific lan client (10.0.0.10) through wireguard. Lan and wireguard addresses are

/ip address
add address=10.0.0.1/24 interface=lan network=10.0.0.0
add address=10.10.10.1/29 interface=wireguard1 network=10.10.10.0

We first create a routing table:

/routing table
add comment="wireguard 1" disabled=no fib name=t-wg1

and add the following rule to the top of /ip/firewall/mangle

/ip firewall mangle
add action=change-mss chain=forward comment="Clamp MSS to PMTU for outgoing packets" \
new-mss=clamp-to-pmtu out-interface=wireguard1 passthrough=yes protocol=tcp tcp-flags=syn

or, per @anav's suggestion:

/ip firewall mangle
add action=change-mss chain=forward new-mss=1380 out-interface=wireguard1 \
protocol=tcp tcp-flags=syn tcp-mss=1381-65535

Afterwards, we mark routing:

add action=mark-routing chain=prerouting comment=Netflix dst-address-list=Netflix \
    in-interface-list=!WAN new-routing-mark=t-wg1 passthrough=no src-address=10.0.0.10
add action=mark-routing chain=prerouting comment="Amazon (Netflix)" dst-address-list=Amazon \
    in-interface-list=!WAN new-routing-mark=t-wg1 passthrough=no src-address=10.0.0.10

Address list 'Netflix' is basically a set of IP4 addresses of AS2906:

/ip firewall address-list
add address=23.246.0.0/18 comment=Netflix list=Netflix
add address=37.77.184.0/21 comment=Netflix list=Netflix
add address=45.57.0.0/17 comment=Netflix list=Netflix
add address=64.120.128.0/17 comment=Netflix list=Netflix
add address=66.197.128.0/17 comment=Netflix list=Netflix
add address=69.53.224.0/19 comment=Netflix list=Netflix
add address=108.175.32.0/20 comment=Netflix list=Netflix
add address=185.2.220.0/22 comment=Netflix list=Netflix
add address=185.9.188.0/22 comment=Netflix list=Netflix
add address=192.173.64.0/18 comment=Netflix list=Netflix
add address=198.38.96.0/19 comment=Netflix list=Netflix
add address=198.45.48.0/20 comment=Netflix list=Netflix
add address=208.75.76.0/22 comment=Netflix list=Netflix

But, since Netflix uses Amazon as its CDN, we also need a list containing certain addresses from AS16509 (see AWS IP address ranges). Not all the addresses from AS16509 are needed, but finding out which one are, is not always trivial. My strategy (client device being a TV) was to route all the traffic through the wireguard for a certain period of time, and 'catch' the IP addresses:

add action=add-dst-to-address-list address-list=TV-Nflx address-list-timeout=\
    none-static chain=prerouting comment="Get Amazon IP" dst-address=\
    !10.0.0.0/24 src-address=10.0.0.10

Afterwards, combining the Amazon addresses collected in 'TV-Nflx' list (the rest you can filter out) and AWS IP address ranges you can create your Amazon address list. For different regions of the world, and for different Netflix subscriptions, this list will (significantly) differ, so you'll have to create it yourself.

In case you already have the list 'Amazon' and need to catch those few addresses which are not present in your list, you can add

dst-address-list=!Amazon

to the previous rule.

In /ip firewall nat you need a src-nat or masquerade rule:

/ip firewall nat
add action=src-nat chain=srcnat comment="wireguard 1" routing-mark=t-wg1 to-addresses=10.10.10.1

And finally in /ip route we add:

/ip route
add comment="wireguard 1" disabled=no distance=1 dst-address=0.0.0.0/0 \
    gateway=wireguard1 pref-src="" routing-table=t-wg1 scope=30 \
    suppress-hw-offload=no target-scope=10

Optionally, you can add a killswitch:

add blackhole comment="killswitch wg" disabled=no distance=10 dst-address=\
    0.0.0.0/0 gateway="" pref-src="" routing-table=t-wg1 scope=250 \
    suppress-hw-offload=no target-scope=10

Optionally, you can add a killswitch

could you specify what this rule does?

I have done everything here step by step and it looks like I am not getting anything to my wireguard :frowning:

does your wireguard generally work, has it been properly set up? (interface, peer, nat masquerade, ip address)

Hi,

I think so, the Czech wireguard is working flawlessly. today it is 4 sleepless night and I still cant see where I made a mistake..

thank you for helping… PS: I live in australia, but currently account is in turkey so nordVPN. my friend has unified udm and he runs ok on that there.

config below

# 2025-08-06 15:18:57 by RouterOS 7.19.4
# software id = 

# model = E50UG
# serial number = HHE6PF
/interface pptp-client
add connect-to=81.0.xxxx max-mtu=1400 name=VPN_CZ user=ppp1
/interface bridge
add name=bridge1 port-cost-mode=short
/interface wireguard
add listen-port=51820 mtu=1420 name=wireguard1
add listen-port=23132 mtu=1450 name=wireguard_becho
add listen-port=45654 mtu=1420 name=wireguard_ben
add listen-port=13231 mtu=1450 name=wireguard_gewi
add listen-port=13233 mtu=1420 name=wireguard_phone
/interface list
add name=WAN
add name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/ip pool
add name=dhcp ranges=192.168.9.2
/ip dhcp-server
add address-pool=dhcp disabled=yes interface=bridge1 name=dhcp1
/routing ospf instance
add disabled=yes name=default-v2
/routing ospf area
add disabled=yes instance=default-v2 name=backbone-v2
/routing table
add fib name=CZ_VPN
add fib name=to-ben-vpn
add comment="wireguard 1" disabled=no fib name=t-wg1
/routing bgp template
set default disabled=yes output.network=bgp-networks routing-table=main
/user group
add name=homeassistant policy="read,test,api,rest-api,!local,!telnet,!ssh,!ftp\
    ,!reboot,!write,!policy,!winbox,!password,!web,!sniff,!sensitive,!romon"
/ip smb
set interfaces=ether1
/interface bridge port
add bridge=bridge1 ingress-filtering=no interface=ether1 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether2 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether4 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether5 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether3 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 interface=*A
add bridge=bridge1 ingress-filtering=no interface=WAN internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface=WAN internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface=WAN internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface=WAN internal-path-cost=10 \
    path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ipv6 settings
set disable-ipv6=yes
/interface detect-internet
set detect-interface-list=all
/interface list member
add interface=ether2 list=LAN
add interface=ether3 list=LAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=VPN_CZ list=WAN
add interface=wireguard_gewi list=WAN
add interface=wireguard_ben list=LAN
add interface=wireguard_becho list=LAN
add interface=ether1 list=LAN
add interface=wireguard1 list=WAN
/interface ovpn-server server
add mac-address=FE:FD:8D:6C:86:B0 name=ovpn-server1
/interface wireguard peers
add allowed-address=0.0.0.0/0 endpoint-address=81.0.xxxx endpoint-port=\
    13231 interface=wireguard_gewi name=peer1 persistent-keepalive=10s \
    public-key="Hk="
add allowed-address=0.0.0.0/0,192.168.0.0/24 endpoint-address=185.14xxxxx \
    endpoint-port=13231 interface=wireguard_becho name=peer2 \
    persistent-keepalive=40s public-key=\
    "CUAu9XA="
add allowed-address=192.168.222.101/32,192.168.222.100/32,192.168.1.0/24 \
    interface=wireguard_ben name=peer9 persistent-keepalive=10s public-key=\
    "qh="
add allowed-address=192.168.111.100/32,192.168.111.101/32 interface=\
    wireguard_phone name="my devices" persistent-keepalive=25s private-key=\
    "AFQxGJ/g==" public-key=\
    "WNqBUc="
add allowed-address=0.0.0.0/0 endpoint-address=87.249xxxx endpoint-port=\
    51820 interface=wireguard1 name="Turkey Nord VPN" persistent-keepalive=5s \
    public-key="mlY5b4BI="
/ip address
add address=192.168.100.3/24 interface=wireguard_gewi network=192.168.100.0
add address=192.168.110.3/24 interface=wireguard_becho network=192.168.110.0
add address=192.168.111.1/24 interface=wireguard_phone network=192.168.111.0
add address=192.168.222.1/24 interface=wireguard_ben network=192.168.222.0
add address=10.5.0.2 interface=wireguard1 network=10.5.0.0
/ip cloud
set ddns-update-interval=1m
/ip cloud advanced
set use-local-address=yes
/ip dhcp-client
add interface=bridge1 use-peer-dns=no
/ip dhcp-server lease
add address=192.168.2.253 client-id=1:f0:b3:ec:16:76:4e mac-address=\
    F0:B3:EC:16:76:4E server=*2
add address=192.168.2.254 client-id=1:a8:51:ab:91:43:3d mac-address=\
    A8:51:AB:91:43:3D server=*2
/ip dhcp-server network
add address=192.168.4.0/24 dns-server=192.168.4.240 gateway=192.168.4.240 \
    netmask=24
/ip dns
set allow-remote-requests=yes cache-size=4096KiB servers=8.8.4.4,8.8.8.8
/ip dns static
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.o2tv\\.cz\$" type=FWD
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.iol\\.cz\$" type=FWD
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.gemius\\.pl\$" type=\
    FWD
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.ceskatelevize\\.cz\$" \
    type=FWD
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.sysct\\.cz\$" type=FWD
add disabled=yes forward-to=192.168.103.1 regexp=".*\\.czech-tv\\.cz\$" type=\
    FWD
add forward-to=192.168.100.1 regexp=".*\\.czech-tv\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.o2tv\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.ceskatelevize\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.sysct\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.iol\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.gemius\\.pl\$" type=FWD
add forward-to=192.168.110.1 regexp=".*\\.tplinkwifi\\.net\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.cetin\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.jyxo\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.jyxo-tls\\.cz\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.conviva\\.com\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.nielsen\\.com\$" type=FWD
add forward-to=192.168.100.1 regexp=".*\\.nielsencollections\\.com\$" type=\
    FWD
add disabled=yes forward-to=192.168.222.101 regexp=".*\\.netflix\\.com\$" \
    type=FWD
add disabled=yes forward-to=192.168.222.101 regexp=".*\\.netflix\\.net\$" \
    type=FWD
add disabled=yes forward-to=192.168.222.101 regexp=".*\\.nflxso\\.net\$" \
    type=FWD
add disabled=yes forward-to=192.168.222.101 regexp=".*\\.nflxvideo\\.net\$" \
    type=FWD
add forward-to=10.5.0.2 regexp=".*\\.netflix\\.com\$" type=FWD
add forward-to=10.5.0.2 regexp=".*\\.netflix\\.net\$" type=FWD
add forward-to=10.5.0.2 regexp=".*\\.nflxso\\.net\$" type=FWD
add disabled=yes forward-to=10.5.0.2 regexp=".*\\.nflxsearch\\.net\$" type=\
    FWD
add forward-to=10.5.0.2 regexp=".*\\.nflxvideo\\.net\$" type=FWD
add disabled=yes forward-to=10.5.0.2 regexp=".*\\nflximg\\.net\$" type=FWD
add disabled=yes forward-to=10.5.0.2 regexp=".*\\nflximg\\.com\$" type=FWD
add disabled=yes forward-to=10.5.0.2 regexp=".*\\nflxext\\.com\$" type=FWD
/ip firewall address-list
add address=192.168.4.190 list=access_vpn
add address=192.168.111.100 list=access_vpn
add address=192.168.4.36 list=access_vpn
add address=192.168.4.69 list=access_vpn
add address=23.246.0.0/18 comment=Netflix list=Netflix
add address=37.77.184.0/21 comment=Netflix list=Netflix
add address=45.57.0.0/17 comment=Netflix list=Netflix
add address=64.120.128.0/17 comment=Netflix list=Netflix
add address=66.197.128.0/17 comment=Netflix list=Netflix
add address=69.53.224.0/19 comment=Netflix list=Netflix
add address=108.175.32.0/20 comment=Netflix list=Netflix
add address=185.2.220.0/22 comment=Netflix list=Netflix
add address=185.9.188.0/22 comment=Netflix list=Netflix
add address=192.173.64.0/18 comment=Netflix list=Netflix
add address=198.38.96.0/19 comment=Netflix list=Netflix
add address=198.45.48.0/20 comment=Netflix list=Netflix
add address=208.75.76.0/22 comment=Netflix list=Netflix
add address=224.0.0.251 list=Amazon
add address=17.57.145.37 list=Amazon
add address=35.190.88.7 list=Amazon
add address=54.91.103.251 list=Amazon
add address=184.31.252.177 list=Amazon
add address=151.101.3.6 list=Amazon
add address=23.48.97.34 list=Amazon
add address=54.164.163.115 list=Amazon
add address=17.253.121.201 list=Amazon
add address=17.253.67.131 list="Amazon  "
add address=17.253.34.131 list=Amazon
add address=17.253.66.37 list=Amazon
add address=17.253.67.140 list=Amazon
add address=17.248.219.18 list=Amazon
add address=17.248.219.66 list=Amazon
add address=85.239.69.39 comment=ns2.sysct.cz list=ct_voyo
add address=85.239.64.136 comment=ns3.sysct.cz list=ct_voyo
add address=50.85.152.114 comment=eboxprod1.tv.cloudapi.cetin.cz list=ct_voyo
add address=104.18.36.244 comment=ws.cms.jyxo.cz list=ct_voyo
add address=172.64.151.12 comment=ws.cms.jyxo.cz list=ct_voyo
add address=199.127.194.109 comment=onprem-ipv4.cws.conviva.com list=ct_voyo
add address=199.127.193.108 comment=onprem-ipv4.cws.conviva.com list=ct_voyo
add address=199.127.194.128 comment=onprem-ipv4.cws.conviva.com list=ct_voyo
add address=172.64.144.48 comment=app-config.cms.jyxo-tls.cz list=ct_voyo
add address=104.18.43.208 comment=app-config.cms.jyxo-tls.cz list=ct_voyo
add address=194.228.98.28 comment=12-str07-3201-prod.tv.cetin.cz list=ct_voyo
add address=194.228.31.79 comment=ingesttls.cms.nova.cz list=ct_voyo
add address=194.228.98.31 comment=12-str08-3201-prod.tv.cetin.cz list=ct_voyo
add address=3.105.196.9 list=TV-Nflx
add address=17.57.145.39 list=TV-Nflx
/ip firewall filter
add action=accept chain=forward in-interface=wireguard_phone
add action=accept chain=input comment="Allow WG from phone" dst-port=13233 \
    protocol=udp
add action=accept chain=forward comment="allow wireguard nord" dst-port=51820 \
    protocol=udp
add action=accept chain=input in-interface=wireguard_ben
add action=accept chain=forward in-interface=wireguard_ben out-interface=\
    bridge1
add action=accept chain=forward in-interface=bridge1 out-interface=\
    wireguard_ben
add action=accept chain=forward out-interface=wireguard1 src-address-list=\
    access_vpn
add action=accept chain=forward out-interface=wireguard1 src-address=\
    192.168.111.0/24
add action=accept chain=forward out-interface=wireguard1 src-address=\
    192.168.4.0/24
add action=accept chain=forward out-interface=wireguard1 src-address=\
    10.5.0.0/24
/ip firewall mangle
add action=change-mss chain=forward comment=\
    "Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pmtu \
    out-interface=wireguard_gewi protocol=tcp tcp-flags=syn
add action=change-mss chain=forward comment=\
    "Clamp MSS to PMTU for Outgoing packets" new-mss=clamp-to-pmtu \
    out-interface=wireguard_ben protocol=tcp tcp-flags=syn
add action=mark-routing chain=prerouting comment="ct a voyo" \
    dst-address-list=ct_voyo log-prefix=ct new-routing-mark=CZ_VPN \
    src-address=192.168.4.36
add action=mark-routing chain=prerouting comment=netflix disabled=yes \
    dst-address-list=netflix new-routing-mark=to-ben-vpn src-address=\
    192.168.4.36
add action=mark-routing chain=prerouting comment="ct a voyo mom ntb" \
    dst-address-list=ct_voyo new-routing-mark=CZ_VPN src-address=\
    192.168.4.178
add action=mark-routing chain=prerouting comment="ct a voyo mom iphone" \
    dst-address-list=ct_voyo new-routing-mark=CZ_VPN src-address=\
    192.168.4.123
add action=change-mss chain=forward comment=\
    "Clamp MSS to PMTU for outgoing packets" new-mss=clamp-to-pmtu \
    out-interface=wireguard1 protocol=tcp tcp-flags=syn
add action=mark-routing chain=prerouting comment=Netflix disabled=yes \
    dst-address-list=Netflix in-interface-list=!WAN new-routing-mark=t-wg1 \
    src-address=192.168.4.36
add action=mark-routing chain=prerouting comment="Amazon (Netflix)" \
    dst-address-list=Amazon in-interface-list=!WAN new-routing-mark=t-wg1 \
    src-address=192.168.4.36
add action=add-dst-to-address-list address-list=TV-Nflx address-list-timeout=\
    none-static chain=prerouting comment="Get Amazon IP" dst-address=\
    !192.168.4.0/24 dst-address-list=!Amazon src-address=192.168.4.36
add action=add-dst-to-address-list address-list=ct_voyo address-list-timeout=\
    none-static chain=prerouting comment="Get voyo IP" disabled=yes \
    dst-address=!192.168.4.0/24 src-address=192.168.4.36
/ip firewall nat
# VPN_CZ not ready
add action=masquerade chain=srcnat out-interface=VPN_CZ
add action=masquerade chain=srcnat out-interface=wireguard_gewi
add action=masquerade chain=srcnat out-interface=wireguard_ben
add action=masquerade chain=srcnat out-interface=wireguard1
add action=src-nat chain=srcnat comment=nordvpn routing-mark=t-wg1 \
    to-addresses=10.5.0.2
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip route
add comment=pptp disabled=yes dst-address=0.0.0.0/0 gateway=192.168.103.1 \
    routing-table=CZ_VPN suppress-hw-offload=no
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=wireguard_gewi \
    pref-src="" routing-table=CZ_VPN scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no dst-address=192.168.0.0/24 gateway=wireguard_becho \
    routing-table=main suppress-hw-offload=no
add comment=pptp disabled=yes distance=1 dst-address=0.0.0.0/0 gateway=VPN_CZ \
    pref-src="" routing-table=CZ_VPN scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no dst-address=192.168.0.0/24 gateway=wireguard_becho \
    routing-table=main suppress-hw-offload=no
add disabled=no distance=1 dst-address=192.168.11.0/24 gateway=\
    wireguard_becho pref-src="" routing-table=main scope=30 \
    suppress-hw-offload=no target-scope=10
add disabled=no distance=1 dst-address=192.168.1.0/24 gateway=wireguard_ben \
    pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=192.168.4.1 \
    pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=10.5.0.2 pref-src="" \
    routing-table=t-wg1 scope=30 suppress-hw-offload=no target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=wireguard1 pref-src=\
    "" routing-table=t-wg1 scope=30 suppress-hw-offload=no target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=192.168.100.1 \
    pref-src="" routing-table=CZ_VPN scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no distance=1 dst-address=192.168.1.0/24 gateway=192.168.222.101 \
    pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
    target-scope=10
add disabled=no distance=1 dst-address=192.168.100.0/24 gateway=\
    wireguard_gewi routing-table=CZ_VPN scope=10 suppress-hw-offload=no \
    target-scope=5
add blackhole disabled=no distance=255 dst-address=0.0.0.0/0 gateway="" \
    routing-table=t-wg1 suppress-hw-offload=no
/ip service
set api disabled=yes
/ip smb shares
set [ find default=yes ] directory=/flash/pub
/routing bfd configuration
add disabled=yes interfaces=all min-rx=200ms min-tx=200ms multiplier=5
add disabled=yes interfaces=all min-rx=200ms min-tx=200ms multiplier=5
add disabled=yes interfaces=all min-rx=200ms min-tx=200ms multiplier=5
/system clock
set time-zone-name=Australia/Brisbane
/system identity
set name="HEX Honza"
/system leds
add interface=ether2 leds=user-led type=interface-activity
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp server
set manycast=yes
/system ntp client servers
add address=195.113.144.201
add address=195.113.144.238
/system routerboard mode-button
set enabled=yes on-event=test-script
/system routerboard settings
set auto-upgrade=yes
/system scheduler
add disabled=yes interval=2s name=voyo on-event="# Only run if 192.168.4.36 is\
    \_reachable\
    \n:if ([/ping 192.168.4.36 count=2] > 0) do={\
    \n\
    \n  :local myServers {\
    \n    \"ivysilani\";\"ceskatelevize\";\"seznam\";\"stream\";\"o2tv\";\"cze\
    ch-tv\";\"iol\";\
    \n    \"sysct\";\"gemius\";\"voyo\";\"cra\";\"nova\";\"sledovanitv\";\"ime\
    dia\";\
    \n    \"sdn\";\"cetin\";\"jyxo\";\"jyxo-tls\";\"conviva\";\"nielsen\"\
    \n  }\
    \n\
    \n  :foreach dnsEntry in=[/ip dns cache all find] do={\
    \n\
    \n    :local name [/ip dns cache all get \$dnsEntry name]\
    \n    :local type [/ip dns cache all get \$dnsEntry type]\
    \n    :local data [/ip dns cache all get \$dnsEntry data]\
    \n\
    \n    :foreach keyword in=\$myServers do={\
    \n\
    \n      :if ([:find \$name \$keyword] != nil) do={\
    \n\
    \n        :local ipToAdd \"\"\
    \n\
    \n        :if (\$type = \"A\") do={\
    \n          :set ipToAdd \$data\
    \n        }\
    \n\
    \n        :if (\$type = \"CNAME\") do={\
    \n          :do {\
    \n            :set ipToAdd [:resolve \$data]\
    \n          } on-error={\
    \n            :log warning \"\E2\9D\8C Failed to resolve CNAME \$data for \
    \$name\"\
    \n          }\
    \n        }\
    \n\
    \n        :if ([:len \$ipToAdd] > 0) do={\
    \n\
    \n          :if ([:len [/ip firewall address-list find list=\"ct_voyo\" ad\
    dress=\$ipToAdd]] = 0) do={\
    \n\
    \n            /ip firewall address-list add list=\"ct_voyo\" address=\$ipT\
    oAdd comment=\$name\
    \n            :log info \"\E2\9C\85 Added \$ipToAdd from \$name to ct_voyo\
    \"\
    \n\
    \n          }\
    \n        }\
    \n      }\
    \n    }\
    \n  }\
    \n\
    \n} else={\
    \n  :log warning \"\E2\9D\8C 192.168.4.36 is not reachable. DNS script abo\
    rted.\"\
    \n}" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-time=startup
add name="Duckdns updater" on-event=\
    "/system script run Duckdns-Dynamic-IP-Updater;" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2025-08-06 start-time=02:29:06
add name=clouddns on-event="/tool fetch url=\"https://ipv4.cloudns.net/api/dyn\
    amicURL/\?q=NTE5MjU5NDozNDI5MTQxODY6MWMzMGFiYTZiMjI3ZWIwOTllNjdkOTRjMTM5Zm\
    VkMjlhYjk4NjAwYzQ5MWRiZTRjNzk0YTA3MjIzZDdiMWQ3Mg\" mode=https" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2025-08-06 start-time=02:30:06
add disabled=yes name=netflix on-event=":local myServers {\"netflix\";\"nflxvi\
    deo\";\"nflxso\";\"nflxext\";\"nflximg\";\"nflxsearch\"}\
    \n\
    \n:foreach dnsEntry in=[/ip dns cache all find] do={\
    \n\
    \n  :local name [/ip dns cache all get \$dnsEntry name]\
    \n  :local type [/ip dns cache all get \$dnsEntry type]\
    \n  :local data [/ip dns cache all get \$dnsEntry data]\
    \n\
    \n  :foreach keyword in=\$myServers do={\
    \n    :if ([:find \$name \$keyword] != nil) do={\
    \n\
    \n      :local ipToAdd \"\"\
    \n\
    \n      :if (\$type = \"A\") do={\
    \n        :set ipToAdd \$data\
    \n      }\
    \n\
    \n      :if (\$type = \"CNAME\") do={\
    \n        :do {\
    \n          :set ipToAdd [:resolve \$data]\
    \n        } on-error={\
    \n          :set ipToAdd \"\"\
    \n          :log warning \"CNAME resolution failed for \$data\"\
    \n        }\
    \n      }\
    \n\
    \n      :if ([:len \$ipToAdd] > 0) do={\
    \n\
    \n        # Remove existing entry to avoid duplicates or comment mismatch\
    \n        :foreach old in=[/ip firewall address-list find address=\$ipToAd\
    d list=\"netflixandamazon\"] do={\
    \n          /ip firewall address-list remove \$old\
    \n        }\
    \n\
    \n        # Add new entry (permanent, with comment)\
    \n        /ip firewall address-list add list=\"netflixandamazon\" address=\
    \$ipToAdd comment=\$name\
    \n        :log info \"\E2\9C\85 Added \$ipToAdd from \$name to netflixanda\
    mazon\"\
    \n\
    \n      }\
    \n    }\
    \n  }\
    \n}" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2025-08-06 start-time=02:28:33
add disabled=yes interval=5s name="netflix and amazon" on-event="# Only run if\
    \_192.168.4.36 is reachable\
    \n:if ([/ping 192.168.4.36 count=2] > 0) do={\
    \n\
    \n :local myServers {\"netflix\";\"nflxvideo\";\"nflxso\";\"nflxext\";\"nf\
    lximg\";\"nflxsearch\"}\
    \n\
    \n  :foreach dnsEntry in=[/ip dns cache all find] do={\
    \n\
    \n    :local name [/ip dns cache all get \$dnsEntry name]\
    \n    :local type [/ip dns cache all get \$dnsEntry type]\
    \n    :local data [/ip dns cache all get \$dnsEntry data]\
    \n\
    \n    :foreach keyword in=\$myServers do={\
    \n\
    \n      :if ([:find \$name \$keyword] != nil) do={\
    \n\
    \n        :local ipToAdd \"\"\
    \n\
    \n        :if (\$type = \"A\") do={\
    \n          :set ipToAdd \$data\
    \n        }\
    \n\
    \n        :if (\$type = \"CNAME\") do={\
    \n          :do {\
    \n            :set ipToAdd [:resolve \$data]\
    \n          } on-error={\
    \n            :log warning \"\E2\9D\8C Failed to resolve CNAME \$data for \
    \$name\"\
    \n          }\
    \n        }\
    \n\
    \n        :if ([:len \$ipToAdd] > 0) do={\
    \n\
    \n          :if ([:len [/ip firewall address-list find list=\"NaA\" addres\
    s=\$ipToAdd]] = 0) do={\
    \n\
    \n            /ip firewall address-list add list=\"NaA\" address=\$ipToAdd\
    \_comment=\$name\
    \n            :log info \"\E2\9C\85 Added \$ipToAdd from \$name to NaA\"\
    \n\
    \n          }\
    \n        }\
    \n      }\
    \n    }\
    \n  }\
    \n\
    \n} else={\
    \n  :log warning \"\E2\9D\8C 192.168.4.36 is not reachable. DNS script abo\
    rted.\"\
    \n}" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2025-08-06 start-time=02:28:33
/system script
add dont-require-permissions=no name=voyo owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
    global ajouteIP do={\
    \n  :if ([:len [/ip firewall address-list find address=\"\$nouvelleIP\" an\
    d list=\"voyo\"]] = 0) do={\
    \n    /ip firewall address-list add list=\"voyo\" address=\$nouvelleIP tim\
    eout=02:00:00\
    \n  }\
    \n}\
    \n\
    \n:local myServers { \"voyo\";\"cra\";\"nova\";\"cetin\";\"jyxo\";\"jyxo-t\
    ls\"}\
    \n/ip dns cache all {\
    \n  :foreach i in=\$myServers do={\
    \n    :foreach j in=[find where (name~\$i)] do={\
    \n      :local myName [get \$j name]\
    \n      :local myType [get \$j type]\
    \n      :local myData [get \$j data]\
    \n      :if (\$myType = \"A\") do={\
    \n        \$ajouteIP nouvelleIP=\$myData\
    \n       }\
    \n\
    \n      :if (\$myType = \"CNAME\") do={\
    \n        :local ipResolue [:resolve \"\$myData\"];\
    \n         \$ajouteIP nouvelleIP=\$ipResolue\
    \n      }\
    \n    }\
    \n  }\
    \n}"
add dont-require-permissions=no name=cloudns owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="/\
    tool fetch url=\"https://ipv4.cloudns.net/api/dynamicURL/\?q=NTE5MjU5NDozN\
    DI5MTQxODY6MWMzMGFiYTZiMjI3ZWIwOTllNjdkOTRjMTM5ZmVkMjlhYjk4NjAwYzQ5MWRiZTR\
    jNzk0YTA3MjIzZDdiMWQ3Mg\" mode=https"
add dont-require-permissions=no name=test-script owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=\
    ":log info message=(\"1234567890\");"
add dont-require-permissions=no name="Cloudflare ddns" owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
    local apiKey \"apikeyapikeyapikeyapikeyapikeyapikeyapikeyapikey\"\r\
    \n:local cfUser \"jaros@freedom21.cz\"\r\
    \n:local zoneID \"zoneIdzoneIdzoneIdzoneIdzoneIdzoneId\"\r\
    \n:local recordID \"recordIDrecordIDrecordIDrecordIDrecordID\"\r\
    \n:local domainName \"example.com\"\r\
    \n\r\
    \n# Do not edit below\r\
    \n\r\
    \n:local currentIP ([/tool fetch url=\"https://ifconfig.me/ip\" mode=https\
    \_output=user as-value]->\"data\")\r\
    \n:local cloudflareDNSIP [:resolve \$domainName server=1.1.1.1];\r\
    \n\r\
    \n:if (\$currentIP != \$cloudflareDNSIP) do={\r\
    \n  # If the IP has changed, update the Cloudflare record\r\
    \n  :log info (\"Updating Cloudflare record. Old IP: \" . \$cloudflareDNSI\
    P . \" New IP: \" . \$currentIP);\r\
    \n\r\
    \n  :local httpHeaders (\"X-Auth-Email: \" . \$cfUser . \"\\r\\nX-Auth-Key\
    : \" . \$apiKey . \"\\r\\nContent-Type: application/json\")\r\
    \n  :local payload (\"{\\\"type\\\":\\\"A\\\",\\\"name\\\":\\\"\" . \$doma\
    inName . \"\\\",\\\"content\\\":\\\"\" . \$currentIP . \"\\\",\\\"ttl\\\":\
    120,\\\"proxied\\\":false}\")\r\
    \n\r\
    \n  /tool fetch mode=https url=\"https://api.cloudflare.com/client/v4/zone\
    s/\$zoneID/dns_records/\$recordID\" http-method=put http-header=\$httpHead\
    ers http-data=\$payload;\r\
    \n}"
add dont-require-permissions=no name=Duckdns-Dynamic-IP-Updater owner=admin \
    policy=read,write,policy,test source="#----------SCRIPT INFORMATION-------\
    --------------------------------------------\
    \n#\
    \n# Script:  Beeyev DuckDNS.org Dynamic DNS Update Script\
    \n# Version: 1.2.1\
    \n# Created: 29/07/2019\
    \n# Updated: 11/08/2022\
    \n# Author:  Alexander Tebiev\
    \n# Website: https://github.com/beeyev\
    \n#\
    \n#----------MODIFY THIS SECTION AS NEEDED--------------------------------\
    --------\
    \n\
    \n# DuckDNS Sub Domain\
    \n:local duckdnsSubDomain \"40bh\"\
    \n\
    \n# DuckDNS Token\
    \n:local duckdnsToken \"04ef3c9a-271e-4de3-b06c-b012d8d42e79\"\
    \n\
    \n# Set true if you want to use IPv6\
    \n:local ipv6mode false;\
    \n\
    \n#-----------------------------------------------------------------------\
    --------\
    \n\
    \n# Online services which respond with your IPv4, two for redundancy\
    \n:local ipDetectService1 \"https://api.ipify.org/\"\
    \n:local ipDetectService2 \"https://ipv4.icanhazip.com/\"\
    \n\
    \n# Online services which respond with your IPv6, two for redundancy\
    \n:local ipv6DetectService1 \"https://api64.ipify.org/\"\
    \n:local ipv6DetectService2 \"https://ipv6.icanhazip.com/\"\
    \n\
    \n#-----------------------------------------------------------------------\
    --------\
    \n\
    \n:local previousIP; :local currentIP\
    \n# DuckDNS Full Domain (FQDN)\
    \n:local duckdnsFullDomain \"\$duckdnsSubDomain.duckdns.org\"\
    \n\
    \n:log warning message=\"START: DuckDNS.org DDNS Update\"\
    \n\
    \nif (\$ipv6mode = true) do={\
    \n\t:set ipDetectService1 \$ipv6DetectService1;\
    \n\t:set ipDetectService2 \$ipv6DetectService2;\
    \n\t:log error \"DuckDNS: ipv6 mode enabled\"\
    \n}\
    \n\
    \n# Resolve current DuckDNS subdomain ip address\
    \n:do {:set previousIP [:resolve \$duckdnsFullDomain]} on-error={ :log war\
    ning \"DuckDNS: Could not resolve dns name \$duckdnsFullDomain\" };\
    \n\
    \n# Detect our public IP adress useing special services\
    \n:do {:set currentIP ([/tool fetch url=\$ipDetectService1 output=user as-\
    value]->\"data\")} on-error={\
    \n\t\t:log error \"DuckDNS: Service does not work: \$ipDetectService1\"\
    \n\t\t#Second try in case the first one is failed\
    \n\t\t:do {:set currentIP ([/tool fetch url=\$ipDetectService2 output=user\
    \_as-value]->\"data\")} on-error={\
    \n\t\t\t:log error \"DuckDNS: Service does not work: \$ipDetectService2\"\
    \n\t\t};\
    \n\t};\
    \n\t\
    \n\
    \n:log info \"DuckDNS: DNS IP (\$previousIP), current internet IP (\$curre\
    ntIP)\"\
    \n\
    \n:if (\$currentIP != \$previousIP) do={\
    \n\t:log info \"DuckDNS: Current IP \$currentIP is not equal to previous I\
    P, update needed\"\
    \n\t:log info \"DuckDNS: Sending update for \$duckdnsFullDomain\"\
    \n\t:local duckRequestUrl \"https://www.duckdns.org/update\\\?domains=\$du\
    ckdnsSubDomain&token=\$duckdnsToken&ip=\$currentIP&verbose=true\"\
    \n\t:log info \"DuckDNS: using GET request: \$duckRequestUrl\"\
    \n\
    \n\t:local duckResponse\
    \n\t:do {:set duckResponse ([/tool fetch url=\$duckRequestUrl output=user \
    as-value]->\"data\")} on-error={\
    \n\t\t:log error \"DuckDNS: could not send GET request to the DuckDNS serv\
    er. Going to try again in a while.\"\
    \n\t\t:delay 5m;\
    \n\t\t\t:do {:set duckResponse ([/tool fetch url=\$duckRequestUrl output=u\
    ser as-value]->\"data\")} on-error={\
    \n\t\t\t\t:log error \"DuckDNS: could not send GET request to the DuckDNS \
    server for the second time.\"\
    \n\t\t\t\t:error \"DuckDNS: bye!\"\
    \n\t\t\t}\
    \n\t}\
    \n\
    \n\t# Checking server's answer\
    \n\t:if ([:pick \$duckResponse 0 2] = \"OK\") do={\
    \n\t\t:log info \"DuckDNS: New IP address (\$currentIP) for domain \$duckd\
    nsFullDomain has been successfully set!\"\
    \n\t} else={ \
    \n\t\t:log warning \"DuckDNS: There is an error occurred during IP address\
    \_update, server did not answer with \\\"OK\\\" response!\"\
    \n\t}\
    \n\
    \n\t:log info \"DuckDNS: server answer is: \$duckResponse\"\
    \n} else={\
    \n\t:log info \"DuckDNS: Previous IP (\$previousIP) is equal to current IP\
    \_(\$currentIP), no need to update\"\
    \n}\
    \n\
    \n:log warning message=\"END: DuckDNS.org DDNS Update finished\""
add dont-require-permissions=no name=netflix owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source=":\
    global ajouteIP do={\r\
    \n  :if ([:len [/ip firewall address-list find address=\"\$nouvelleIP\" an\
    d list=\"netflix\"]] = 0) do={\r\
    \n    /ip firewall address-list add list=\"netflix\" address=\$nouvelleIP \
    timeout=02:00:00\r\
    \n  }\r\
    \n}\r\
    \n\r\
    \n:local myServers { \"netflix\";\"nflxso\";\"nflxvideo\"}\r\
    \n/ip dns cache all {\r\
    \n  :foreach i in=\$myServers do={\r\
    \n    :foreach j in=[find where (name~\$i)] do={\r\
    \n      :local myName [get \$j name]\r\
    \n      :local myType [get \$j type]\r\
    \n      :local myData [get \$j data]\r\
    \n      :if (\$myType = \"A\") do={\r\
    \n        \$ajouteIP nouvelleIP=\$myData\r\
    \n       }\r\
    \n\r\
    \n      :if (\$myType = \"CNAME\") do={\r\
    \n        :local ipResolue [:resolve \"\$myData\"];\r\
    \n         \$ajouteIP nouvelleIP=\$ipResolue\r\
    \n      }\r\
    \n    }\r\
    \n  }\r\
    \n}"
/tool sniffer
set file-limit=20000KiB file-name=mac filter-interface=ether4 memory-limit=\
    2000KiB

if you first declare that add interface=wireguard1 list=WAN and then try to mark routing like this:
add action=mark-routing chain=prerouting comment="Amazon (Netflix)" \ dst-address-list=Amazon in-interface-list=!WAN new-routing-mark=t-wg1 \ src-address=192.168.4.36
no package in interface wireguard1 will get marked, because it belongs to list WAN.
Same holds for the previous line with dst-address-list=Netflix, which should be enabled.

Try disabling add interface=wireguard1 list=WAN

This was just a quick look, maybe there are more errors…

Side note: Amazon addresses will mostly be /15 and /16 blocks, and not individual /32 addresses
Side note 2: filter section of firewall effectively doesn’t do anything, since all the rules are ‘accept’

Edit: changed ‘try to’ part

I fixed that, no difference, getting "we’re having problem connecting to netflix

thank you for your help


“we’re having problem connecting to netflix” can originate from:

  1. incorrect/incomplete list of IP addresses which should be routed through the specific wireguard interface and/or
  2. IP addresses should be routed through the specific wireguard, but they’re not actually getting routed through that interface

Check with traceroute from 192.168.4.36 whether the package to, say, 35.190.1.1 goes through wireguard1. If yes, the problem is not the wireguard, but the address list

taking that back

trace route is working

netflix on my computer

I have this script to get the ip for CZ tv, but I dont know why but my 7.19.4 mikrotik struggles with writing it properly to the list

# Only run if 192.168.4.36 is reachable
:if ([/ping 192.168.4.36 count=2] > 0) do={

 :local myServers {"netflix";"nflxvideo";"nflxso";"nflxext";"nflximg";"nflxsearch"}

  :foreach dnsEntry in=[/ip dns cache all find] do={

    :local name [/ip dns cache all get $dnsEntry name]
    :local type [/ip dns cache all get $dnsEntry type]
    :local data [/ip dns cache all get $dnsEntry data]

    :foreach keyword in=$myServers do={

      :if ([:find $name $keyword] != nil) do={

        :local ipToAdd ""

        :if ($type = "A") do={
          :set ipToAdd $data
        }

        :if ($type = "CNAME") do={
          :do {
            :set ipToAdd [:resolve $data]
          } on-error={
            :log warning "❌ Failed to resolve CNAME $data for $name"
          }
        }

        :if ([:len $ipToAdd] > 0) do={

          :if ([:len [/ip firewall address-list find list="NaA" address=$ipToAdd]] = 0) do={

            /ip firewall address-list add list="NaA" address=$ipToAdd comment=$name
            :log info "✅ Added $ipToAdd from $name to NaA"

          }
        }
      }
    }
  }

} else={
  :log warning "❌ 192.168.4.36 is not reachable. DNS script aborted."
}```

from what I can see, the route properly goes through wireguard1 (195.88.86.124 is in Turkey, and 10.5.0.1 is the server side address of wireguard1), i.e. the packet/routing marking works properly :slight_smile:

man, you were right… I asked chat gpt to give me more IPs

added

103.87.204.0/22
185.2.220.0/22
185.9.188.0/22
185.53.48.0/22
192.173.64.0/18
198.38.96.0/19
198.45.48.0/20
207.45.72.0/22
207.45.76.0/22
208.75.76.0/22

and it started to work

last 3 days LOL

I wish that script worked better

thank you, one nodge and make all the difference

PS the wireguard as WAN or disabled has no affect on it

yay, it works! :slight_smile:
Amazon IPs are tricky, what works today, may not necessarily work tomorrow, so having a good script to ‘catch’ the IP’s and add them to the list is quite important…

yeah, I suck in programming and guess who suck as well…

chatGPT :DDD

how do you open the vpn for all to access from my Apple TV so I can properly capture with your solution in mangle?

not sure that I properly understood it, but one way of 'catching addresses' could be like this:

/ip firewall mangle

add action=mark-connection chain=prerouting comment="TV collect IP" \
    dst-address=!192.168.4.0/24 dst-address-list=!Netflix \
    new-connection-mark=my-mark passthrough=yes src-address=192.168.4.36
	
add action=add-dst-to-address-list address-list=TV-LIST-NFLX address-list-timeout=\
    none-static chain=prerouting comment="TV collect IP" connection-mark=\
    my-mark dst-address=!192.168.4.0/24 dst-address-list=!Amazon src-address=\
    192.168.4.36

The first line checks if the IP is already in the list 'Netflix'; if not, the connection gets marked. The second line checks whether any of the addresses marked in the previous step is in the list 'Amazon'. If not, it gets added to the list 'TV-LIST-NFLX'.
That list will contain the addresses which then need to be matched/filtered against AWS IP addresses (link in original post), because TV-LIST-NFLX will contain many other addresses which have nothing to do with netflix/amazon.

could you please have a look, I have a vpn to a friend and his ip is 192.168.1.0/24 but once I set up the mangle it goes to turkey as well. but the ip is not in the list at all :frowning: cant find the issue

If the target is to have LAN clients being able to access the remote LAN subnet, then a good example can be found in Mikrotik's official documentation for wireguard.

Also: a torch from the router, using wireguard_nord_turkey won't help in diagnosing why a LAN client can't see the remote LAN, behind the totally different wireguard interface. Packets originating from the router do not go through mangle-prerouting chain (see here).

I am pinging from my computer, to that other wireguard network, and it shows torch on the turkey interface.. that’s what I meant, but the network is not part of Netflix/Amazon list