i just got my first Mikrotik () and am trying to configure it properly. i have internet working right now for my AT&T Business Fiber internet, but i'm not getting the full gigabit up and down i'm supposed to be getting. additionally the Mikrotik really seems to have some high CPU when running these speed tests which leads me to believe that either a) its a hardware offloading problem, or b) ive set up routing incorrectly and packets are getting dropped/duplicated. i get approximately 500mbit down on fast.com and speedtest.com when it should be 1gbit.
some notes: internet comes through an ethernet SFP adapter on SFP1 via VLAN 2. it gets routed to the LAN bridge that bridges all other ports together. its a pretty standard config outside of the VLAN.
does anyone see any issues with my config? what would be some debugging steps i could take?
thank you a ton!
here is my export:
Code: Select all
[admin@MikroTik] > export
# 2024-04-02 23:13:51 by RouterOS 7.14.2
# software id = T2XZ-91S8
#
# model = CRS310-8G+2S+
/interface bridge
add admin-mac=D4:01:C3:10:XX:XX auto-mac=no comment=defconf name=bridge port-cost-mode=short protocol-mode=none
/interface ethernet
set [ find default-name=sfp-sfpplus1 ] mac-address=F8:F5:32:A4:XX:XX
/interface vlan
add interface=sfp-sfpplus1 name=att-vlan2 vlan-id=2
/interface list
add name=WAN
add name=LAN
/ip pool
add name=dhcp ranges=10.0.1.0/24
/ip dhcp-server
add address-pool=dhcp interface=bridge name=dhcp1
/interface bridge port
add bridge=bridge comment=defconf interface=ether1 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether2 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether3 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether4 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether5 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether6 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether7 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=ether8 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf interface=sfp-sfpplus2 internal-path-cost=10 path-cost=10
/interface dot1x client
add certificate=Client_00XXXX-27373200029XXXX.pem_0 eap-methods=eap-tls identity=F8:F5:32:A4:XX:XX interface=sfp-sfpplus1
/interface list member
add interface=bridge list=LAN
add interface=att-vlan2 list=WAN
/ip address
add address=10.0.1.1/24 interface=bridge network=10.0.1.0
/ip dhcp-client
add interface=att-vlan2
/ip dhcp-server network
add address=0.0.0.0/24 dns-server=0.0.0.0 gateway=0.0.0.0 netmask=24
add address=10.0.1.0/24 dns-server=10.0.1.1 gateway=10.0.1.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip firewall filter
add action=accept chain=input comment="accept established,related" connection-state=established,related
add action=drop chain=input connection-state=invalid
add action=accept chain=input comment="allow ICMP" in-interface=att-vlan2 protocol=icmp
add action=drop chain=input comment="block everything else" in-interface=att-vlan2
/ip firewall nat
add action=masquerade chain=srcnat out-interface=att-vlan2