Community discussions

Search found 6 matches

by Petrovich
Thu Mar 19, 2015 11:40 pm
Forum: RouterBOARD hardware
Topic: CCR IPSec performance
Replies: 40
Views: 15495

Re: CCR IPSec performance

Alright, how normis got his very nice numbers with their CCRs? I think it is hard for TileGX performs so slowly with encryption even with one core... How many CCR cores were loaded in your tests with encryption enabled? In my case only one core was loaded. It is an issue. I hope normis will comment...
by Petrovich
Fri Feb 13, 2015 4:42 pm
Forum: RouterBOARD hardware
Topic: CCR IPSec performance
Replies: 40
Views: 15495

Re: CCR IPSec performance

What was your test procedure? That was two CCR-1036-8G-2S+ instances connected with 10Gbit/s link. GRE over IPSEC. Confuguration is almost default, you can find it here (just not to replear myselft). http://forum.mikrotik.com/viewtopic.php?p=467392#p467392 I had two laptops with gigabit ethernet ad...
by Petrovich
Mon Feb 09, 2015 2:49 pm
Forum: RouterBOARD hardware
Topic: CCR IPSec performance
Replies: 40
Views: 15495

Re: CCR IPSec performance

max throughput 3.2Gbps with 34 tunnels (full duplex)

520Mbps with one GRE over IpSec tunnel (full duplex)



Tested with traffic-generator and 1470byte packets.
Could you please provide your settings for this tunnel.
I did not manage to get even 200Mbit/s on CCR-1036
by Petrovich
Thu Feb 05, 2015 2:41 pm
Forum: General
Topic: IPSec between two CCR1036 poor performance
Replies: 17
Views: 3344

Re: IPSec between two CCR1036 poor performance

Have the same issue with two CCR1036 I've connected them with 10Gbit/s link and set up gre tunnel with IPSEC with aes-256 I have up to 80Mbit/s, with aes-128 without authentication I have up to 150Mbit/s While downloading file through IPSEC one CPU on each router is 100% loaded. All other cores are ...
by Petrovich
Thu Feb 05, 2015 2:29 pm
Forum: General
Topic: Cloud Core Router reboots with sha512 auth algorithm
Replies: 1
Views: 1058

Re: Cloud Core Router reboots with sha512 auth algorithm

/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha512
Forgot to mention that everything is OK, if I change algorithms to sha256 or sha1 or null
by Petrovich
Thu Feb 05, 2015 2:25 pm
Forum: General
Topic: Cloud Core Router reboots with sha512 auth algorithm
Replies: 1
Views: 1058

Cloud Core Router reboots with sha512 auth algorithm

What is the correct way to report bugs? I have two CCR1036-8G-2S+ with following config: /ip ipsec proposal set [ find default=yes ] auth-algorithms=sha512 /ip ipsec peer add address=10.20.0.1/32 dh-group=modp4096 enc-algorithm=aes-256 hash-algorithm=sha256 nat-traversal=no secret=123 /ip ipsec poli...