/ip firewall address-list add address=192.168.5.0/24 list=under_protonvpn /ip firewall mangle add action=mark-connection chain=prerouting src-address-list=under_protonvpn new-connection-mark=under_protonvpn passthrough=yes /interface/wireguard/add name=protonwg01 private-key="privatekey" comment="ProtonVPN interface" /interface/wireguard/peers/add endpoint-address=138.199.22.91 endpoint-port=51820 public-key="publickey" allowed-address=0.0.0.0/1,128.0.0.0/1 interface=protonwg01 /ip/address/add address=10.2.0.2/30 interface=protonwg01 /ip/dns/set servers=10.2.0.1 allow-remote-requests=yes /routing/table/add name=protonvpn_wg fib /ip/firewall/mangle/add chain=prerouting src-address-list=under_protonvpn action=mark-routing new-routing-mark=protonvpn_wg passthrough=yes /ip/route/add routing-table=protonvpn_wg dst-address=0.0.0.0/0 gateway=protonwg01 comment="ProtonVPN Wireguard default route" /interface/bridge/add name=protonvpn_blackhole protocol-mode=none /routing/table/add name=protonvpn_blackhole fib /ip/firewall/mangle/add chain=prerouting src-address-list=under_protonvpn action=mark-routing new-routing-mark=protonvpn_blackhole passthrough=yes /ip/route/add routing-table=protonvpn_blackhole gateway=protonvpn_blackhole /ip firewall mangle add action=change-mss chain=forward new-mss=1360 passthrough=yes protocol=tcp connection-mark=under_protonvpn tcp-flags=syn tcp-mss=!0-1375