I do not watch YouTube that often, but the ads get on my nerves whenever I do. For a while, I paid for Turkish YouTube Premium through my Apple account. That worked until recently, when I could no longer renew it. I did not feel like paying more for Premium, so I decided to try a nerdier way around the ads. And it seems to work.

In some countries YouTube serves fewer or no ads. My workaround is to send only YouTube traffic through a VPN endpoint in one of them. I chose Andorra because it is the closest to where I live, and it worked for me. The rest of the network still uses my normal internet connection (ah, except Cloudflare during LaLiga football matches). I used NordVPN with IKEv2/IPsec on my MikroTik router. You can use another VPN provider or protocol too.

Get the VPN working first

You need a MikroTik router running RouterOS 7 and a VPN provider that supports manual connections through IKEv2/IPsec, WireGuard, or OpenVPN.

Honestly, OpenVPN on MikroTik was a pain for me. I could not get it working with my provider. RouterOS has its own OpenVPN implementation with documented limitations, including missing NCP cipher negotiation. That does not explain every connection problem, but for this setup I would choose WireGuard or IKEv2/IPsec.

I used IKEv2/IPsec. Here is an example based on my NordVPN configuration, with the endpoint and credentials replaced by placeholders. Use an actual IKEv2 hostname from your provider. For NordVPN, follow the certificate import steps in MikroTik’s official setup guide first; other providers have their own instructions. Bring up the tunnel before adding the YouTube rules below.

My IKEv2/IPsec configuration
/ip ipsec mode-config
add connection-mark=VPNYouTube name=VPNYouTube responder=no use-responder-dns=no

/ip ipsec policy group
add name=VPNYouTube

/ip ipsec profile
add name=VPNYouTube

/ip ipsec peer
add address="<IKEV2_SERVER_HOSTNAME>" exchange-mode=ike2 \
    name=VPNYouTube profile=VPNYouTube

/ip ipsec proposal
add name=VPNYouTube pfs-group=none

/ip ipsec identity
add auth-method=eap eap-methods=eap-mschapv2 \
    generate-policy=port-strict mode-config=VPNYouTube peer=VPNYouTube \
    policy-template-group=VPNYouTube \
    username="<VPN_SERVICE_USERNAME>" password="<VPN_SERVICE_PASSWORD>"

/ip ipsec policy
add dst-address=0.0.0.0/0 src-address=0.0.0.0/0 template=yes \
    group=VPNYouTube proposal=VPNYouTube

The identity uses EAP-MSCHAPv2 and the provider’s service credentials. Other providers may need different authentication or encryption settings. The VPNYouTube connection mark is what ties this configuration to the firewall rule below.

The traffic split

With the VPN connected, the next job is to send YouTube traffic through it. To do that, the router needs to know which destination IP addresses belong to YouTube. I have not found a complete official list from Google, but there are open-source projects that collect these addresses and update their lists automatically.

My network uses only IPv4, so the commands below cover IPv4. If you use IPv6, you will also need an IPv6 address list and matching firewall and VPN routing settings. Otherwise those connections can still go through your normal internet connection.

Download the YouTube IP ranges

I chose touhidurrr/iplist-youtube. It collects addresses through DNS lookups and automatically updates the lists. It also provides a RouterOS script, so I can import the addresses directly into my router.

These lists can miss addresses or include unrelated ones. Shared CDN ranges can also send other traffic through the VPN. Choose a source you trust and check its contents before using it.

There is another risk here: /import executes RouterOS commands. The example below downloads a script from the internet and runs it on the router every day. A malicious change to that file could change your router configuration with the permissions granted to the script. HTTPS verifies the connection, not whether the downloaded commands are safe. Review the source before enabling automatic imports; for more control, use a reviewed copy that you update yourself.

My refresh script downloads the file and imports it into the youtube firewall address list. The scheduler runs it once a day at 00:20, and the last command runs it immediately for the initial setup. The upstream file currently clears and rebuilds youtube, leaving separate lists such as my cloudflare-ips alone.

Paste this into the RouterOS terminal:

/system script
add name=youtube-iplist-refresh policy=ftp,read,write,policy,test source={
    :log info "Refreshing YouTube IP list"
    /tool fetch url="https://raw.githubusercontent.com/touhidurrr/iplist-youtube/main/lists/routeros.rsc" \
        mode=https check-certificate=yes dst-path=youtube-iplist.rsc
    /import file-name=youtube-iplist.rsc
}

/system scheduler
add name=youtube-iplist-refresh interval=1d start-time=00:20:00 \
    on-event=youtube-iplist-refresh policy=ftp,read,write,policy,test

/system script run youtube-iplist-refresh

After it completes, check that the list has entries:

/ip firewall address-list print count-only where list=youtube

Mark YouTube before the general routing rules

Now the router has the destination list. The next rule checks connections coming from the LAN: if the destination is in youtube and the connection has no mark yet, it labels that connection VPNYouTube.

The IPsec mode config above uses the same label to generate a dynamic source NAT rule. That rule translates marked connections to the address assigned by the VPN server, so they match the tunnel’s IPsec policy.

The example assumes you already have an interface list named LAN containing your home network interfaces, such as your LAN bridge. Check it in WinBox under Interfaces → Interface List, or with /interface list member print. If your list has a different name, replace LAN below.

Add this rule, then move it above any general load-balancing or policy-routing rules in your mangle list:

/ip firewall mangle
add chain=prerouting action=mark-connection \
    comment="route YouTube through VPN" \
    in-interface-list=LAN connection-mark=no-mark \
    dst-address-list=youtube dst-address-type=!local \
    new-connection-mark=VPNYouTube

The mark belongs to the connection, so subsequent packets keep it. Connections to destinations outside the list continue to follow your usual routing rules.

If you already use rules to split traffic between multiple internet connections, put the YouTube rule above them. Otherwise those rules may assign a different connection mark first.

Also check your firewall’s FastTrack rules before testing. FastTrack speeds up forwarding but bypasses IPsec processing, so exclude connections marked VPNYouTube. If your FastTrack rule already matches only connection-mark=no-mark, these connections are excluded. Otherwise adjust its conditions in WinBox, or temporarily disable FastTrack while testing. MikroTik explains this behavior in its connection tracking documentation.

Check that it is working

First, clear the router’s tracked connections so YouTube starts new ones with the new rules. This interrupts active connections across your network and may disconnect your router management session, so run it from your local network when you can tolerate a brief interruption:

/ip firewall connection remove [find]

Then open YouTube and play a few videos. Check whether they load and whether you still see ads. While a video is playing, you can check the router too:

/ip firewall mangle print stats where comment="route YouTube through VPN"
/ip firewall connection print where connection-mark=VPNYouTube
/ip ipsec active-peers print

The first command shows how much traffic has matched the YouTube rule. The second shows connections marked VPNYouTube, and the third shows active IPsec peers. These checks help confirm that traffic is being selected and the tunnel is connected; watching videos is still the test for ads.

If the rule’s counter stays at zero, check that the youtube list has entries and that the rule is above your general routing rules. If YouTube stops loading, check that the tunnel is up and that VPN traffic is excluded from FastTrack.

You may also need to clear YouTube’s cache on your device, or clear YouTube cookies and site data in your browser. That can sign you out. For a mobile app, try clearing its data or reinstalling it, then signing in again.

Android TV took me much longer to get working. As soon as I sent YouTube through the VPN, it stopped opening entirely, both in the YouTube app and in the TV’s browser. Clearing the cache did not help. I eventually removed the YouTube app and all its cached data, installed it again, and signed in again. Only then did it work for me.

To undo this later, disable or remove the mangle rules and the VPN policy. The default route for the rest of the network does not need to change.

Happy adless watching!