WAN

Change which interfaces are tagged as the foreign and domestic uplinks, and manage the masking VPN clients.

Last updated Aug 14, 2026View as Markdown

Overview

The WAN tab is where you rework the uplink assignments you made in the wizard without running the wizard again. It has three sections: Foreign / Starlink and Domestic, listing the interfaces tagged for each role, and Starlink Masking VPN Client, listing the VPN clients that conceal the Starlink IP.

Each uplink section carries a Change button that opens the same interface picker the wizard uses, and each row can be moved to the other category.

Before you start

  • Changing an uplink rewrites routing on the router, so expect a brief interruption. The page waits a few seconds after a change before reloading the interface list.
  • An interface can only be tagged as one uplink at a time.

Steps

  1. Open the WAN tab.
  2. To reassign an uplink, press Change on Foreign / Starlink or Domestic. Pick the interface type and interface in the dialog; if it is wireless, fill in the SSID and password. Press Save.
  3. To move an interface between roles, use its row action and confirm in the Move to Domestic or Move to Foreign dialog.
  4. To manage the masking tunnel, use New on the Starlink Masking VPN Client section, or edit an existing client from its row.

Reference

Section What it lists
Foreign / Starlink Interfaces tagged as the foreign (Starlink) uplink.
Domestic Interfaces tagged as the domestic uplink.
Starlink Masking VPN Client VPN clients that conceal the Starlink IP.
Column What it shows
Name The interface name.
Type Interface type.
Detail Addressing or link detail for that interface.
Enabled Whether the interface is up.

Troubleshooting

“Failed to load interfaces”. The panel could not read the interface list. Check the router is reachable and the session credentials are valid.

“Failed to load VPN”. The VPN client list could not be read. The uplink sections still work.

A changed uplink does not show up immediately. The page deliberately waits a few seconds after a change before refreshing, so RouterOS has time to settle.