Resolving PRC Portal Session Drops in MikroTik Dual-WAN Environments Without Sacrificing Aggregated Bandwidth

Category: MikroTik RouterOS / Network Engineering • ROS Version: RouterOS v7















1. Executive Summary & Problem Statement

In Dual-WAN RouterOS configurations utilizing Per Connection Classifier (PCC) with the both-addresses-and-ports classifier, network operators can successfully deliver aggregated bandwidth ("Combined Speed") across multi-threaded applications, video streaming, and speed tests.

However, sensitive local infrastructure—specifically the Professional Regulation Commission (PRC) CPDAS portal (cpdas.prc.gov.ph)—frequently fails to load, returning ERR_CONNECTION_REFUSED or persistent HTTP connection timeouts.

Root Cause Analysis

Modern web portals enforce strict IP Session Tracking to prevent session hijacking. Under the both-addresses-and-ports PCC scheme, individual client HTTP/HTTPS requests (such as fetching static assets, scripts, or authentication tokens) are dynamically load-balanced across WAN 1 and WAN 2. Consequently, the target server detects rapid source IP fluctuations within a single session, flags the traffic as a security anomaly, and terminates the connection.

2. Limitations of Conventional Approaches

  • Approach 1: Migrating to src-address-and-port Classification
    Drawback: While this stabilizes session tracking by pinning a client socket to a single WAN, it eliminates multi-WAN single-client speed aggregation, breaching SLAs or marketing promises made to clients regarding combined speeds.
  • Approach 2: Manual Destination Address Lists
    Drawback: Highly inefficient. Modern government platforms utilize dynamic content delivery networks (CDNs) and cloud infrastructures with frequently shifting IP blocks, leading to recurring connectivity issues as IP lists become obsolete.

3. The Solution: Dynamic Wildcard TLS (SNI) Inspection

Rather than maintaining static IP tables or reducing global PCC efficiency, traffic steering can be handled during the initial SSL/TLS Handshake (TCP Port 443) using Server Name Indication (SNI) matching via tls-host="*.gov.ph".

By evaluating the requested hostname prior to PCC execution, the router dynamically steers matching traffic to a designated primary WAN link without requiring pre-resolved destination IP addresses.

4. Implementation Guide (RouterOS v7)

Step 1: Configure High-Priority Mangle Rules

Insert the TLS bypass rules at the top of the Mangle table (Index 0) to ensure execution prior to the general PCC classification chain.

/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=80,443 tls-host="*.gov.ph" action=mark-connection new-connection-mark=prc_conn passthrough=yes comment="Auto Bypass ALL PH Gov Sites (PRC Fix)" place-before=0
add chain=prerouting connection-mark=prc_conn action=mark-routing new-routing-mark=prc-route passthrough=no comment="Route Gov Traffic via Dedicated WAN" place-before=1

Note: Map prc-route to your preferred single-WAN routing table (e.g., Globe/ISP1).

Step 2: Retain Core PCC Aggregation

Ensure existing PCC rules remain positioned below the bypass rules to maintain multi-WAN load balancing for standard web traffic.

Mangle Rule Order:
[Rule 0] Wildcard TLS Inspection (*.gov.ph) → Single-WAN Route (Ensures Session Stability)
[Rule 1+] Default PCC Engine (2/0, 2/1) → Load-Balanced Multi-WAN (Ensures Aggregated Speed)

5. Key Outcomes & Benefits

1. Uninterrupted Portal Access

Complete session stability across cpdas.prc.gov.ph and related .gov.ph subdomains with zero connection drops.

2. Preserved Aggregated Speed

General clients retain full multi-WAN combined speeds for non-sensitive data transfers and speed testing.

3. Zero Maintenance

Automated domain-level matching eliminates the administrative overhead of tracking dynamic IP address lists.

Comments

Popular posts from this blog

AdGuard Home DNS for Newbies - Part 3

Suricata on Mikrotik(IDS+IPS) = Part 4 - Configuration of the IPS Part

DHCP for Dummies: How Your Devices Get Online Without You Lifting a Finger