I am considering putting a Mikrotik into my cloud as core router. Now, the CCR series is nice - but most are so low throughput it is not funny. My cloud backbone runss on 200g per server (2x100g) backboned in a Mellanox switch. Before anyone starts complaining about internet speeds- this is not the point here, we talk totally “in data center backbone transfer speed”. I can live with a lot less on the internet, but the internet does not copy VM’s between domains in the same data center.
What would one advice as router between networks in this scenario?
My requirements are:
- Routing IPV4 and IPV6
- limited firewall capability (not all subnets accessing all other subnets, something that CAN be done with routing tables, not the real firewall). Mostly I hava “hub and spoke” network - one central ip range and then client ranges and all must be able to reach the central one, but not go further.
- VPN Termination a BIG plus.
- Reverse Proxy for HTTP a small plus
- As much routing performance as possible. Given that the indivisual networks CAN run 200g throughput, I can live with 10g routing, but I can not live with the central file server being behing a 1g connection. Not if that includes install images that may see concurrent use.
My alternatives are so far - but I am VERY open to something else:
- Just use Microsoft Network Controller plus a Mikrotik as VPN Termination for clients
- Use CHR, but I find no information how much throughput has been recorded there using proper Hyper-V virtualization and high end network cards.Seems noone even tried it out with more than 10g - and that is not exactly high throughput in a cloud environment these days.
- Use a dedicated box with an X64 license 64 bit, but I seriously think I will have to do that using 10G - or does Mikrotik offer drivers for Mellanox 100G cards?
- Use ???. The https://mikrotik.com/product/CCR1072-1G-8Splus - CCR 1072 - looks nice and can hange 10xSFP+, which translates into 10x 10g - which theoretically can be used to do a lot of dedicated 10G with a 100g/10G breakout (i.e. dedicate 10G for the central network, leave another 10G for distribution to end user points, and use a 3rd one for VPN. A LOT more ports than I think to need now, but if that is what it takes - it is not bad. The only alternative routers sadly offer max 2x SFP+ (CCR1036-8G-2S+). THAT one would actually work perfectly (alloning me to use 8x1G as “breakout” for stuff like KVM, control networks etc.) and having 2x10G. Any known issues with this one?