External Proxy Server for Mikrotik

Ditulis oleh Beri komentar(27) Lihat komentar

Mikrotik routerboard has a built-in proxy in it, but it has main constraint : very limited storage capacity. Therefore, most network administrators whom using mikrotik will use an external proxy to overcome this constraint. Here you can found an easy ways to implementing external proxy server for Mikrotik.

Squid is the most widely used proxy daemon for linux (including its derivative such as lusca). Some several advantages in the implementation of external proxy are :

  • Easy to adjust the configuration to suite your needs
  • The use of access control lists (ACLs) that can be used for specific purposes
  • Squid (especially version 2.7) can be “armed” with a url redirector. In some condition, url redirector can be used to force squid to cache dynamic content (such as Youtube videos).
  • Greater storage capacity as the general computer or server use the harddisk as data storage.

In this post, I’ll describe how to integrate external proxy with mikrotik using 2 methods : using NAT or using mangle.

Annotation :

  1. Mikrotik to proxy IP address :
  2. Proxy to Mikrotik IP address :
  3. Clients IP address :
First method : Using NAT
We can used Mikrotik built in NAT to forward HTTP request (port 80) from clients to external proxy.
/ip firewall address-list
add address= list=ip-proxy
/ip firewall nat
add action=dst-nat chain=dstnat comment="transparent proxy" dst-port=80 protocol=tcp src-address-list=!ip-proxy to-addresses= to-ports=3128

Explanation :

First, we define IP address class for proxy server.

/ip firewall address-list
add address= list=ip-proxy

Then add new rule on NAT to forward http  request to external proxy.

/ip firewall nat
add action=dst-nat chain=dstnat comment=”transparent proxy” dst-port=80 protocol=tcp src-address-list=!ip-proxy to-addresses= to-ports=3128

Second method : Using built-in mangle

/ip route
add check-gateway=ping distance=1 gateway= routing-mark=to-ext-proxy
/ip firewall mangle
add action=mark-routing chain=prerouting comment="mark routing to proxy" dst-port=80 new-routing-mark=to-ext-proxy protocol=tcp src-address=

Another method to forward http requests from clients is using mangle by adding new route. This method will work if external proxy able to act as gateway.

Explanation :

First, add route to external proxy.

/ip route
add check-gateway=ping distance=1 gateway= routing-mark=to-ext-proxy

Then, mark http requests from all clients to use route to external proxy.

/ip firewall mangle
add action=mark-routing chain=prerouting comment=”mark routing to proxy” dst-port=80 new-routing-mark=to-ext-proxy protocol=tcp src-address=

Proxy server requirements :

You may need to configure some options in order to make it works for both methods such as enabling IPv4 forwarding (by editing systcl.conf) and allowing access to port 3128 in iptables. Add the following lines into the file /etc/rc.local then save :

route add default gateway
iptables -A PREROUTING -t nat -j REDIRECT -p tcp -s -d 0/0 --dport 80 --to-ports 3128
iptables -A INPUT -p tcp -s -d -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p tcp -s --sport 3128 -d -m state --state ESTABLISHED -j ACCEPT

Incoming keywords

mikrotik squid tproxy, mikrotik transparent proxy squid, redirect external proxy squid3 di mikrotik

Related Posts

Filed under


| Tags:

, ,

Leave a comment ?


  1. Boss, why Not working for me, After configure with my working transparent proxy ,i even unable to ping google .

    [root@nat ~]# route
    Kernel IP routing table
    Destination Gateway Genmask Flags Metric Ref Use Iface
    182.160.-.- * U 0 0 0 eth0 * U 0 0 0 eth1
    link-local * U 1002 0 0 eth0
    link-local * U 1003 0 0 eth1
    default UG 0 0 0 eth1
    default 182.160.-.- UG 0 0 0 eth0
    gat:eth0 wan ip
    [root@nat ~]# iptables -L -n
    Chain INPUT (policy ACCEPT)
    target prot opt source destination
    ACCEPT tcp — tcp dpt:3128

    Chain FORWARD (policy ACCEPT)
    target prot opt source destination
    ACCEPT all —
    ACCEPT all —

    Chain OUTPUT (policy ACCEPT)
    target prot opt source destination
    ACCEPT tcp — tcp spt:3128 state ESTABLISHED

  2. using
    rhel 6.4
    squid 3.1

    • I am assuming you are using 2 interface, right? (eth0 and eth1). This tutorial only use single interface and using mikrotik router as gateway. In short, this tutorial wouldn’t meet your requirements. :)

      flush your iptables rules and use this rules:

      iptables -t nat -A PREROUTING -i eth1 -p tcp –dport 80 -j REDIRECT –to-port 3128
      iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

      and don’t forget to set IPv4 forwarding in sysctl. good luck! :)

  3. Yes, Now all traffic going to squid.
    But the only one ip add
    I need all client original ip address.
    how it is possible.Please help
    Thanks in advance.

    • hello shaon. sorry for my late response.

      with current iptables rules, all incoming connection in eth1 with dest. port 80 (http) should be redirected to squid. re-check your squid configuration (squid.conf), ensure your have configuration like this:

      http_port 3128 intercept

      next thing to do is, use your squid box IP address ( as your clients gateway. use google dns as your clients primary/secondary DNS.

      if you installing dns resolver in your squid box (eg. pdnsd, bind, dnsmasq, etc), you can use as clients primary dns server. hope that help. :)

  4. sir im usind squid alternative proxy server
    i want to raoute all proxy:3128 to incoming request assume my proxy server should act as gateway im not using mikrotek board im using simple wireless router and i want my machine be able to use net using proxy if as gateway and the ip lease which i allowed in proxy server e.g netmask gateway which is proxy ip

    i can use my proxy using web proxy setting but i wanted to use it wihout web setthing means directly i get access to web using proxy as gateway

    • right now im doing it as test or educational purpose proxy is virtual and net i want in physical machine plz advice

    • I am assuming your proxy act as gateway + dhcp server, using two interface (eg. eth0 = internet, eth1 = lan), and able to connect to internet properly . in order to make clients browse internet through proxy without setting up proxy manually on browser, you need to setup squid with transparent / intercept configuration directive as described here :


      and finally, redirect all http access to proxy using iptables. you can read detailed how-to here :


      it is not necessary to set static route, since it only useful for proxy box with single network interface.

  5. i tried last step but didn’t worked for me i think add route should solve my problem can u correct me if route is the solve with example route command for redirecting incoming port 80 request

Leave a Comment