CCR-1009-7G IPSec throughput/HW acceleration clarification and if mangle rules affect them

I read some posts about this but they were old and seemed to refer to some older versions of RouterOS with issues. I just want to know:

  1. What is the approximate max throughput of IPSec tunnel on the CCR-1009-7G with HW acceleration?

  2. Does HW acceleration work properly with current versions of RouterOS, any caveats?

  3. Do IP firewall mangle rules such as MSS clamp and connection marks affect/disable the HW acceleration? If so, how fast can it go with CPU alone?

  4. What’s the max throughput each single tunnel/connection can reach, if it’s different from overall capacity due to multi-core design?

Your advice would be greatly appreciated!

If you’re thinking about encryption acceleration, then CCR doesn’t offer it. Even if a device does offer encryption in hardware, it doesn’t interfere with framing functions (such as MSS clamping).

On this page:

https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Hardware_acceleration

It lists “Cloud Core Series” as having support for hardware acceleration for the common DES and AES encryptions. Is this info wrong or did I miss something?