8 MBit /sec top :-(

Gents, I’m pulling my hair (not that I have any) out for I don’t know how long… but now it’s time to get help…
We have 20 CRS226 and 10 CRS125 that behave the same with a new setup…
I have following config:

[admin@du-conv-2-CRS226] > /export compact 
# may/19/2016 13:54:45 by RouterOS 6.35.2
# software id = DTVP-NVAP
#
/interface ethernet
set [ find default-name=ether2 ] master-port=ether1
set [ find default-name=ether3 ] master-port=ether1
set [ find default-name=ether4 ] master-port=ether1
set [ find default-name=ether5 ] master-port=ether1
set [ find default-name=ether6 ] master-port=ether1
set [ find default-name=ether7 ] master-port=ether1
set [ find default-name=ether8 ] master-port=ether1
set [ find default-name=ether9 ] master-port=ether1
set [ find default-name=ether10 ] master-port=ether1
set [ find default-name=ether11 ] master-port=ether1
set [ find default-name=ether12 ] master-port=ether1
set [ find default-name=ether13 ] master-port=ether1
set [ find default-name=ether14 ] master-port=ether1
set [ find default-name=ether15 ] master-port=ether1
set [ find default-name=ether16 ] master-port=ether1
set [ find default-name=ether17 ] master-port=ether1
set [ find default-name=ether18 ] master-port=ether1
set [ find default-name=ether19 ] master-port=ether1
set [ find default-name=ether20 ] master-port=ether1
set [ find default-name=ether21 ] master-port=ether1
set [ find default-name=ether22 ] master-port=ether1
set [ find default-name=ether23 ] master-port=ether1
set [ find default-name=ether24 ] master-port=ether1
set [ find default-name=sfp-sfpplus1 ] master-port=ether1 name=sfp1
/interface vlan
add interface=ether1 name=Mgmt vlan-id=2311
add interface=ether1 name=Public vlan-id=2312
add interface=ether1 name=VxBackend vlan-id=2313
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=Demo4-CRS226
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-128-cbc
/interface ethernet switch egress-vlan-tag
add tagged-ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24,sfp1 vlan-id=2311
add tagged-ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20 vlan-id=2312
add tagged-ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20 vlan-id=2313
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=2311 ports=ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16
add customer-vid=0 new-customer-vid=2312 ports=ether21,ether22,ether23,ether24,sfp1
/interface ethernet switch vlan
add ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24,sfp1 vlan-id=2312
add ports=switch1-cpu,ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24,sfp1 vlan-id=2311
add ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20 vlan-id=2313
add ports=switch1-cpu,ether1,ether17,ether18,ether19,ether20 vlan-id=0
/ip address
add address=192.168.27.250/22 interface=Public network=192.168.24.0
add address=10.114.2.250/24 interface=Mgmt network=10.114.2.0
/ip dns
set servers=8.8.8.8
/ip route
add distance=1 gateway=192.168.24.1
/system clock
set time-zone-name=Asia/Dubai
/system identity
set name=du-conv-2-CRS226
/system leds
set 0 interface=sfp1
set 1 interface=sfp1
set 2 interface=sfpplus2
set 3 interface=sfpplus2
/system routerboard settings
set protected-routerboot=disabled
/tool romon port
add
[admin@du-conv-2-CRS226] >

Now between port 24 and port 21 going from vlan 2311 to vlan Public I get @ most 8MBit, 600pps
I don’t know what to do any more

Someone an idea ?

Hi,

Did you check what speed that ports is running at?

Also check cpu usage, maybe you have some firewall rule that is going crazy

Nothing of the sort , no firewall rules (all in private ip space, so I don’t mind)
CPU usage is 5-6% , so no worries there