Am I doing something wrong or is it normal?

Hi..
I have RB2011UiAS-2HnD with default firewall rules. Only ipsec vpn on it and all traffic routed to ipsec..

[admin@Home] > ip firewall/nat print 
Flags: X - disabled, I - invalid; D - dynamic 
 0    ;;; Routing
      chain=srcnat action=accept src-address=10.10.2.2-10.10.2.254 dst-address=0.0.0.0/0 src-address-list=!Device log=no 
      log-prefix="" 
1    ;;; Internet
      chain=srcnat action=masquerade out-interface=ether1 log=no log-prefix=""

With this conf, my profile;
2022-09-19 12_32_13.png
There are 70-100 clients behind Mikrotik. Is it normal ?

RB2011 is not listed as able of HW offloading encryption in this lsit. So yes, what you see is very probably normal.