Resolving PRC Portal Session Drops in MikroTik Dual-WAN Environments Without Sacrificing Aggregated Bandwidth
Category: MikroTik RouterOS / Network Engineering • ROS Version: RouterOS v7
1. Executive Summary & Problem Statement
In Dual-WAN RouterOS configurations utilizing Per Connection Classifier (PCC) with the both-addresses-and-ports classifier, network operators can successfully deliver aggregated bandwidth ("Combined Speed") across multi-threaded applications, video streaming, and speed tests.
However, sensitive local infrastructure—specifically the Professional Regulation Commission (PRC) CPDAS portal (cpdas.prc.gov.ph)—frequently fails to load, returning ERR_CONNECTION_REFUSED or persistent HTTP connection timeouts.
Root Cause Analysis
Modern web portals enforce strict IP Session Tracking to prevent session hijacking. Under the both-addresses-and-ports PCC scheme, individual client HTTP/HTTPS requests (such as fetching static assets, scripts, or authentication tokens) are dynamically load-balanced across WAN 1 and WAN 2. Consequently, the target server detects rapid source IP fluctuations within a single session, flags the traffic as a security anomaly, and terminates the connection.
2. Limitations of Conventional Approaches
-
Approach 1: Migrating to
src-address-and-portClassification
Drawback: While this stabilizes session tracking by pinning a client socket to a single WAN, it eliminates multi-WAN single-client speed aggregation, breaching SLAs or marketing promises made to clients regarding combined speeds. -
Approach 2: Manual Destination Address Lists
Drawback: Highly inefficient. Modern government platforms utilize dynamic content delivery networks (CDNs) and cloud infrastructures with frequently shifting IP blocks, leading to recurring connectivity issues as IP lists become obsolete.
3. The Solution: Dynamic Wildcard TLS (SNI) Inspection
Rather than maintaining static IP tables or reducing global PCC efficiency, traffic steering can be handled during the initial SSL/TLS Handshake (TCP Port 443) using Server Name Indication (SNI) matching via tls-host="*.gov.ph".
By evaluating the requested hostname prior to PCC execution, the router dynamically steers matching traffic to a designated primary WAN link without requiring pre-resolved destination IP addresses.
4. Implementation Guide (RouterOS v7)
Step 1: Configure High-Priority Mangle Rules
Insert the TLS bypass rules at the top of the Mangle table (Index 0) to ensure execution prior to the general PCC classification chain.
/ip firewall mangle
add chain=prerouting protocol=tcp dst-port=80,443 tls-host="*.gov.ph" action=mark-connection new-connection-mark=prc_conn passthrough=yes comment="Auto Bypass ALL PH Gov Sites (PRC Fix)" place-before=0
add chain=prerouting connection-mark=prc_conn action=mark-routing new-routing-mark=prc-route passthrough=no comment="Route Gov Traffic via Dedicated WAN" place-before=1
Note: Map prc-route to your preferred single-WAN routing table (e.g., Globe/ISP1).
Step 2: Retain Core PCC Aggregation
Ensure existing PCC rules remain positioned below the bypass rules to maintain multi-WAN load balancing for standard web traffic.
[Rule 0] Wildcard TLS Inspection (*.gov.ph) → Single-WAN Route (Ensures Session Stability)
[Rule 1+] Default PCC Engine (2/0, 2/1) → Load-Balanced Multi-WAN (Ensures Aggregated Speed)
5. Key Outcomes & Benefits
1. Uninterrupted Portal Access
Complete session stability across cpdas.prc.gov.ph and related .gov.ph subdomains with zero connection drops.
2. Preserved Aggregated Speed
General clients retain full multi-WAN combined speeds for non-sensitive data transfers and speed testing.
3. Zero Maintenance
Automated domain-level matching eliminates the administrative overhead of tracking dynamic IP address lists.

Comments
Post a Comment