Hi All,
Could someone explain why my ccr20024 is just getting 2.4 Gbps download. I have 4 pcs 1 GBPS WAN line.
Regards,
Alex
Please provide an export of your full config (minus any sensitive stuff). Without it, it’s impossible to give you a useful response.
Isn't it a interLAN or interVLAN traffic cumulated as we do not see all the traffic.
Here is the config. I transfer the existing config of ccr2004 to ccr2116 and the same result. we are getting the same download speed 2.4 Gbps.
/interface bridge
add name=bridge1
/interface ethernet
set [ find default-name=sfp-sfpplus1 ] comment="10G LAN Line" name=
LAN-CONNECTION
set [ find default-name=ether1 ] name=WAN1
set [ find default-name=ether2 ] name=WAN2
set [ find default-name=ether3 ] name=WAN3
set [ find default-name=ether4 ] disabled=yes name=WAN4
/interface vlan
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX-test vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
add interface=LAN-CONNECTION name=XX vlan-id=XX
/interface list
add name=LAN
/ip pool
add name="FTTH MAIN IP POOL" ranges=100.100.0.2-100.100.63.254
add name=BusinessClients ranges=172.16.100.10-172.16.100.253
add name=CHRC-BS-POLICY-POOL ranges=10.69.0.2-10.69.1.254
add name="ISP 1 POOL" ranges=172.16.50.10-172.16.50.100
add name="ISP 2 POOL" ranges=172.16.51.10-172.16.51.100
add name="ISP 3 POOL" ranges=172.16.52.10-172.16.52.100
add name="ISP 4 POOL" ranges=172.16.53.10-172.16.53.100
/port
set 0 name=serial0
/ppp profile
add dns-server=8.8.8.8,8.8.4.4 local-address=100.100.0.1 name="80 Mbps"
rate-limit=84992k/84992k remote-address="FTTH MAIN IP POOL"
add dns-server=8.8.8.8,8.8.4.4 local-address=100.100.0.1 name="30 Mbps"
rate-limit=33792k/33792k remote-address="FTTH MAIN IP POOL"
add dns-server=8.8.8.8,8.8.4.4 local-address=100.100.0.1 name="25 Mbps"
rate-limit=28672k/28672k remote-address="FTTH MAIN IP POOL"
add dns-server=8.8.8.8,8.8.4.4 local-address=100.100.0.1 name="50 Mbps"
rate-limit=54272k/54272k remote-address="FTTH MAIN IP POOL"
add local-address=172.16.100.1 name=BusinessClients rate-limit=50M/50M
remote-address=BusinessClients
add dns-server=8.8.8.8,8.8.4.4 local-address=10.69.0.1 name=CHRC-BS-POLICY
remote-address=CHRC-BS-POLICY-POOL
add local-address=172.16.50.1 name="ISP-1 FULL" remote-address="ISP 1 POOL"
add local-address=172.16.51.1 name="ISP-2 FULL" remote-address="ISP 2 POOL"
add local-address=172.16.52.1 name="ISP-3 FULL" remote-address="ISP 3 POOL"
add local-address=172.16.53.1 name="ISP-4 FULL" remote-address="ISP 4 POOL"
/interface sstp-client
add connect-to=195.184.246.1 disabled=no name=sstp-out1 port=9999 profile=
default-encryption user=bicolwireless
/queue simple
add disabled=yes max-limit=44M/44M name=40MB target=100.100.63.254/32
add disabled=yes max-limit=44M/44M name=SpeedTest packet-marks=SpeedTest
parent=40MB target=""
/routing table
add disabled=no fib name=BusinessClients
add disabled=no fib name=public-ip
add disabled=no fib name=isp1
add disabled=no fib name=isp2
add disabled=no fib name=isp3
add disabled=no fib name=isp4
add disabled=no fib name=PBR-ISP1
add disabled=no fib name=PBR-ISP2
add disabled=no fib name=PBR-ISP3
add disabled=no fib name=PBR-ISP4
/ip firewall connection tracking
set enabled=yes
/interface list member
add interface=LAN-CONNECTION list=LAN
/interface ovpn-server server
add mac-address=FE:29:E0:C0:1A:20 name=ovpn-server1
/interface pppoe-server server
add default-profile="30 Mbps" disabled=no interface=SINIBARAN service-name=
SINIBARAN
add default-profile="30 Mbps" disabled=no interface=SINALMACAN service-name=
SINALMACAN
add default-profile="30 Mbps" disabled=no interface=POROPANDAN service-name=
POROPANDAN
add default-profile="30 Mbps" disabled=no interface=GADGARON service-name=
GADGARON
add default-profile="30 Mbps" disabled=no interface=TABUNAN service-name=
TABUNAN
add default-profile="30 Mbps" disabled=no interface=MAJUMLAD service-name=
NAJUMLAD
add default-profile="30 Mbps" disabled=no interface=CAMACHILES service-name=
CAMACHELIS
add default-profile="30 Mbps" disabled=no interface=CALOOCAN service-name=
CALOOCAN
add default-profile="30 Mbps" disabled=no interface=CULASI service-name=
BALOCAWE
add default-profile="30 Mbps" disabled=no interface=CULASI-test service-name=
BANWAN-DAAN
add interface=LAN-CONNECTION service-name=PPPAlex
/ip address
add address=192.168.100.1/24 interface=LAN-CONNECTION network=192.168.100.0
add address=123.253.137.168/26 interface=WAN1 network=123.253.137.128
add address=172.100.100.1/24 interface=LAN-CONNECTION network=172.100.100.0
add address=10.10.0.1/18 interface=LAN-CONNECTION network=10.10.0.0
add address=123.253.137.172/26 interface=WAN2 network=123.253.137.128
add address=123.253.137.173/26 interface=WAN3 network=123.253.137.128
add address=123.253.137.174/26 interface=WAN4 network=123.253.137.128
add address=192.168.200.1/24 interface=ether9 network=192.168.200.0
add address=100.100.0.1/18 interface=SINIBARAN network=100.100.0.0
add address=10.0.0.1/18 interface=LAN-CONNECTION network=10.0.0.0
add address=172.16.100.1/24 interface=bridge1 network=172.16.100.0
add address=172.200.200.1/24 interface=sfp-sfpplus2 network=172.200.200.0
add address=11.0.0.1/18 interface=LAN-CONNECTION network=11.0.0.0
add address=172.200.100.1/24 comment="For WAN2" interface=LAN-CONNECTION
network=172.200.100.0
add address=172.200.101.1/24 comment="For WAN3" interface=LAN-CONNECTION
network=172.200.101.0
add address=172.200.102.1/24 comment="For WAN4" interface=LAN-CONNECTION
network=172.200.102.0
add address=172.16.50.1/24 comment=PBR-WAN1 interface=bridge1 network=
172.16.50.0
add address=172.16.51.1/24 comment=PBR-WAN2 interface=bridge1 network=
172.16.51.0
add address=172.16.52.1/24 comment=PBR-WAN3 interface=bridge1 network=
172.16.52.0
add address=172.16.53.1/24 comment=PBR-WAN4 interface=bridge1 network=
172.16.53.0
/ip dhcp-server network
add address=10.10.0.0/18 comment="hotspot network" gateway=10.10.0.1
add address=12.0.0.0/24 comment="hotspot network" gateway=12.0.0.1
add address=172.168.0.0/18 comment="hotspot network" gateway=172.168.0.1
/ip dns
set servers=8.8.8.8,8.8.4.4
/ip firewall address-list
add address=iphaven.cloud list=public-ip
add address=10.69.0.0/23 comment=CHRC-BS-BLOCKED list=CHRC-BS-BLACKLIST
add address=bicolwis.com comment=CHRC-BS-ALLOWED list=CHRC-BS-WHITELIST
/ip firewall filter
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
add action=accept chain=forward comment=CHRC-BS-ACCEPT dst-address-list=
CHRC-BS-WHITELIST
add action=drop chain=forward comment=CHRC-BS-DROP dst-port=!80 protocol=tcp
src-address-list=CHRC-BS-BLACKLIST
add action=drop chain=forward comment=CHRC-BS-DROP dst-port=443 protocol=tcp
src-address-list=CHRC-BS-BLACKLIST
add action=drop chain=forward comment=CHRC-BS-DROP dst-port=443 protocol=udp
src-address-list=CHRC-BS-BLACKLIST
add action=fasttrack-connection chain=forward comment=FastTrack
connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="Accept Established/Related"
connection-state=established,related
add action=drop chain=forward comment="Drop Invalid" connection-state=invalid
/ip firewall mangle
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new in-interface=WAN1 new-connection-mark=isp1_conn
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new in-interface=WAN2 new-connection-mark=isp2_conn
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new in-interface=WAN3 new-connection-mark=isp3_conn
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new in-interface=WAN4 new-connection-mark=isp4_conn
add action=mark-routing chain=output connection-mark=isp1_conn
new-routing-mark=isp1
add action=mark-routing chain=output connection-mark=isp2_conn
new-routing-mark=isp2
add action=mark-routing chain=output connection-mark=isp3_conn
new-routing-mark=isp3
add action=mark-routing chain=output connection-mark=isp4_conn
new-routing-mark=isp4
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new dst-address-type=!local in-interface-list=LAN
new-connection-mark=isp1_conn per-connection-classifier=
both-addresses-and-ports:4/0
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new dst-address-type=!local in-interface-list=LAN
new-connection-mark=isp2_conn per-connection-classifier=
both-addresses-and-ports:4/1
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new dst-address-type=!local in-interface-list=LAN
new-connection-mark=isp3_conn per-connection-classifier=
both-addresses-and-ports:4/2
add action=mark-connection chain=prerouting connection-mark=no-mark
connection-state=new dst-address-type=!local in-interface-list=LAN
new-connection-mark=isp4_conn per-connection-classifier=
both-addresses-and-ports:4/3
add action=mark-routing chain=prerouting connection-mark=isp1_conn
in-interface-list=LAN new-routing-mark=isp1
add action=mark-routing chain=prerouting connection-mark=isp2_conn
in-interface-list=LAN new-routing-mark=isp2
add action=mark-routing chain=prerouting connection-mark=isp3_conn
in-interface-list=LAN new-routing-mark=isp3
add action=mark-routing chain=prerouting connection-mark=isp4_conn
in-interface-list=LAN new-routing-mark=isp4
add action=mark-packet chain=prerouting comment=SpeedTest disabled=yes
dst-port=8080 new-packet-mark=SpeedTest passthrough=no protocol=tcp
src-port=""
add action=mark-packet chain=prerouting disabled=yes dst-port=""
new-packet-mark=SpeedTest passthrough=no protocol=tcp src-port=8080
add action=mark-packet chain=prerouting disabled=yes new-packet-mark=All
passthrough=no
add action=accept chain=prerouting dst-address=172.16.100.0/24 src-address=
172.16.100.0/24
add action=mark-routing chain=prerouting new-routing-mark=BusinessClients
src-address=172.16.100.0/24
add action=mark-routing chain=prerouting dst-address-list=public-ip
new-routing-mark=public-ip passthrough=no
add action=mark-routing chain=prerouting comment=PBR-ISP1 new-routing-mark=
PBR-ISP1 passthrough=no src-address=172.16.50.0/24
add action=mark-routing chain=prerouting comment=PBR-ISP2 new-routing-mark=
PBR-ISP2 passthrough=no src-address=172.16.51.0/24
add action=mark-routing chain=prerouting comment=PBR-ISP3 new-routing-mark=
PBR-ISP3 passthrough=no src-address=172.16.52.0/24
add action=mark-routing chain=prerouting comment=PBR-ISP4 new-routing-mark=
PBR-ISP4 passthrough=no src-address=172.16.53.0/24
/ip firewall nat
add action=masquerade chain=srcnat out-interface=WAN1
add action=masquerade chain=srcnat out-interface=WAN2
add action=masquerade chain=srcnat out-interface=WAN3
add action=masquerade chain=srcnat out-interface=WAN4
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=192.168.100.0/24
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=172.100.100.0/24
add action=masquerade chain=srcnat comment="10G MATNOG HOTSPOT ROUTER"
src-address=172.200.200.0/24
add action=passthrough chain=unused-hs-chain comment=
"place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=192.168.100.0/24
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=192.168.200.0/24
add action=masquerade chain=srcnat comment="masquerade hotspot network"
src-address=172.100.100.0/24
add action=masquerade chain=srcnat comment="SXX VLAN XX" src-address=
100.100.0.0/18
add action=masquerade chain=srcnat comment="SXX VLAN XX" disabled=yes
src-address=100.110.0.0/21
add action=masquerade chain=srcnat comment="Gadgaron VLAN xX" disabled=yes
src-address=100.120.0.0/21
add action=masquerade chain=srcnat comment="XX" src-address=
10.0.0.0/18
add action=masquerade chain=srcnat comment="XX Network" src-address=
10.10.0.0/18
add action=masquerade chain=srcnat comment="Matnog IP" src-address=
11.0.0.0/18
add action=masquerade chain=srcnat comment=BusinessClients src-address=
172.16.100.0/24
add action=masquerade chain=srcnat comment="For WAN2" src-address=
172.200.100.0/24
add action=masquerade chain=srcnat comment="For WAN3" src-address=
172.200.101.0/24
add action=masquerade chain=srcnat comment="For WAN4" src-address=
172.200.102.0/24
add action=masquerade chain=srcnat out-interface=sstp-out1
add action=masquerade chain=srcnat comment=CHRC-BS-SRCNAT src-address-list=
CHRC-BS-BLACKLIST
add action=redirect chain=dstnat comment=CHRC-BS-DSTNAT dst-port=80 protocol=
tcp src-address-list=CHRC-BS-BLACKLIST to-ports=8082
add action=dst-nat chain=dstnat comment="Port Portward, WAN2: Home Router"
dst-address=123.253.137.172 dst-port=2233 protocol=tcp to-addresses=
172.100.100.7 to-ports=2233
add action=dst-nat chain=dstnat comment=
"Port Portward, WAN3: Sua FTTH Router" dst-address=123.253.137.173
dst-port=2233 protocol=tcp to-addresses=192.168.100.11 to-ports=2233
add action=dst-nat chain=dstnat comment="Port Portward, WAN2: Home Router"
dst-address=123.253.137.172 dst-port=2233 protocol=udp to-addresses=
172.100.100.7 to-ports=2233
add action=dst-nat chain=dstnat comment=
"Port Portward, WAN3: Sua FTTH Router" dst-address=123.253.137.173
dst-port=2233 protocol=udp to-addresses=192.168.100.11 to-ports=2233
add action=masquerade chain=srcnat comment=PBR1 src-address=172.16.50.0/24
add action=masquerade chain=srcnat comment=PBR2 src-address=172.16.51.0/24
add action=masquerade chain=srcnat comment=PBR3 src-address=172.16.52.0/24
add action=masquerade chain=srcnat comment=PBR4 src-address=172.16.53.0/24
/ip proxy
set enabled=yes port=8082 src-address=0.0.0.0
/ip proxy access
add comment=CHRC-BS-ACL-ACCEPT dst-host=bicolwis.com src-address=10.69.0.0/23
add action=redirect action-data=
"bicolwis.com/portal.php?uname=nanflexal&tab=1" comment=
CHRC-BS-ACL-REDIRECT dst-host=!bicolwis.com dst-port=80,443,8082
src-address=10.69.0.0/23
add action=deny comment=CHRC-BS-ACL-DENY dst-port=!80 src-address=
10.69.0.0/23
/ip route
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=123.253.137.129%WAN4
routing-table=main scope=30 target-scope=10
add disabled=yes distance=2 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=3 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=4 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=123.253.137.129%WAN3
routing-table=main scope=30 target-scope=10
add disabled=yes distance=2 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=3 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=4 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=123.253.137.129%WAN2
routing-table=main scope=30 target-scope=10
add disabled=yes distance=2 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=3 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=yes distance=4 dst-address=0.0.0.0/0 gateway=123.253.137.129
routing-table=main scope=30 target-scope=10
add disabled=no distance=1 dst-address=0.0.0.0/0 gateway=123.253.137.129%WAN1
routing-table=main scope=30 target-scope=10
add disabled=no dst-address=0.0.0.0/0 gateway=sstp-out1 routing-table=
public-ip
add comment=isp1 disabled=no distance=1 dst-address=8.8.8.8/32 gateway=
123.253.137.129%WAN1 routing-table=isp1 scope=30 target-scope=10
add comment=isp2 disabled=no distance=1 dst-address=8.8.8.8/32 gateway=
123.253.137.129%WAN2 routing-table=isp2 scope=30 target-scope=10
add comment=isp3 disabled=no distance=1 dst-address=8.8.8.8/32 gateway=
123.253.137.129%WAN3 routing-table=isp3 scope=30 target-scope=10
add comment=isp4 disabled=no distance=1 dst-address=8.8.8.8/32 gateway=
123.253.137.129%WAN4 routing-table=isp4 scope=30 target-scope=10
add comment=isp1-gw disabled=no distance=1 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN1 routing-table=isp1 scope=30 target-scope=10
add comment=isp2-gw disabled=no distance=1 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN2 routing-table=isp2 scope=30 target-scope=10
add comment=isp3-gw disabled=no distance=1 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN3 routing-table=isp3 scope=30 target-scope=10
add comment=isp4-gw disabled=no distance=1 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN4 routing-table=isp4 scope=30 target-scope=10
add comment=PBR-ISP1 disabled=no distance=2 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN1 routing-table=PBR-ISP1 scope=30 target-scope=10
add comment=PBR-ISP2 disabled=no distance=2 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN2 routing-table=PBR-ISP2 scope=30 target-scope=10
add comment=PBR-ISP2 disabled=no distance=2 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN3 routing-table=PBR-ISP3 scope=30 target-scope=10
add comment=PBR-ISP2 disabled=no distance=2 dst-address=0.0.0.0/0 gateway=
123.253.137.129%WAN4 routing-table=PBR-ISP4 scope=30 target-scope=10
/ip service
set ftp disabled=yes
set telnet disabled=yes
set ssh port=2233
set api disabled=yes
set api-ssl disabled=yes
/routing rule
add action=lookup disabled=no dst-address=8.8.8.8/32 src-address="" table=
isp1
add action=lookup disabled=no dst-address=8.8.8.8/32 src-address="" table=
isp2
add action=lookup disabled=no dst-address=8.8.8.8/32 src-address="" table=
isp3
add action=lookup disabled=no dst-address=8.8.8.8/32 src-address="" table=
isp4
/system clock
set time-zone-name=Asia/Manila
/system identity
set name="Main Router"
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=0.asia.pool.ntp.org
/system routerboard settings
set enter-setup-on=delete-key
/system scheduler
add interval=10s name=ISP1 on-event=ISP1-check policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
start-date=2026-04-11 start-time=14:51:22
add interval=10s name=ISP2 on-event=ISP2-check policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
start-date=2026-04-11 start-time=14:51:22
add interval=10s name=ISP3 on-event=ISP3-check policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
start-date=2026-04-11 start-time=14:51:22
add interval=10s name=ISP4 on-event=ISP4-check policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon
start-date=2026-04-11 start-time=14:51:22
/system script
add dont-require-permissions=yes name=ISP1-check owner=admin policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="i
nterface/monitor WAN1 once do={\r
\n\r
\n :local ip ($"local-address")\r
\n :local current [/tool netwatch get value-name=src-address isp1_check]\r
\n\r
\n :if ($current != $ip) do={\r
\n\r
\n /tool netwatch set src-address=$ip [find name="isp1_check"]\r
\n /routing/rule set src-address=$ip [find table=isp1]\r
\n\r
\n }\r
\n \r
\n}"
add dont-require-permissions=yes name=ISP2-check owner=admin policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="i
nterface/monitor WAN2 once do={\r
\n\r
\n :local ip ($"local-address")\r
\n :local current [/tool netwatch get value-name=src-address isp2_check]\r
\n\r
\n :if ($current != $ip) do={\r
\n\r
\n /tool netwatch set src-address=$ip [find name="isp2_check"]\r
\n /routing/rule set src-address=$ip [find table=isp2]\r
\n\r
\n }\r
\n \r
\n}"
add dont-require-permissions=yes name=ISP3-check owner=admin policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="i
nterface/monitor WAN3 once do={\r
\n\r
\n :local ip ($"local-address")\r
\n :local current [/tool netwatch get value-name=src-address isp3_check]\r
\n\r
\n :if ($current != $ip) do={\r
\n\r
\n /tool netwatch set src-address=$ip [find name="isp3_check"]\r
\n /routing/rule set src-address=$ip [find table=isp3]\r
\n\r
\n }\r
\n \r
\n}"
add dont-require-permissions=yes name=ISP4-check owner=admin policy=
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="i
nterface/monitor WAN4 once do={\r
\n\r
\n :local ip ($"local-address")\r
\n :local current [/tool netwatch get value-name=src-address isp4_check]\r
\n\r
\n :if ($current != $ip) do={\r
\n\r
\n /tool netwatch set src-address=$ip [find name="isp4_check"]\r
\n /routing/rule set src-address=$ip [find table=isp4]\r
\n\r
\n }\r
\n \r
\n}"
/tool netwatch
add comment="ISP1 MONITORING" disabled=no down-script=
"ip route disable [find comment="isp1-gw"]" host=8.8.8.8 http-codes=""
name=isp1_check src-address="" test-script="" type=icmp up-script=
"ip route enable [find comment="isp1-gw"]"
add comment="ISP2 MONITORING" disabled=no down-script=
"ip route disable [find comment="isp2-gw"]" host=8.8.8.8 http-codes=""
name=isp2_check src-address="" test-script="" type=icmp up-script=
"ip route enable [find comment="isp2-gw"]"
add comment="ISP3 MONITORING" disabled=no down-script=
"ip route disable [find comment="isp3-gw"]" host=8.8.8.8 http-codes=""
name=isp3_check src-address="" test-script="" type=icmp up-script=
"ip route enable [find comment="isp3-gw"]"
add comment="ISP4 MONITORING" disabled=no down-script=
"ip route disable [find comment="isp4-gw"]" host=8.8.8.8 http-codes=""
name=isp4_check src-address="" test-script="" type=icmp up-script=
"ip route enable [find comment="isp4-gw"]"
/tool romon
set enabled=yes
Please use < / > "Preformatted text" tag to mark code. It makes it more readable and the post does not take nth screens to scroll.
Sort "Tx" column to see which interface makes the highest traffic, sum all values if they sum to 2.4 and so on.
If you have 4 ISP lines, each 1Gb, then the traffic ~2.4Gb is just ~60% of total one. What is wrong?
How many PPoE clients do you have? Average policy of 40Mb makes ~100 clients to saturate all your ISP lines.
You have proxy active so it's hard to say what is going on.
You have no DNS access firewalled from WAN side so you can be a DDOS victim or "trampoline" for others.
This is my network.
My problem, Download speed is stuck to 2.4 Gbps even 4 WAN is Active then a while ago i remove WAN4 leaving my ccr2116 with 3 WAN Active and still got 2.4 Gbps with 3 WAN lines.
Then i load WAN4 to seperate router and getting 600 Mbps download. Im not sure where the problem but my ISP told me that theire NAP support 10Gbps per NAP.
Does switch use MIkrotik 10G DAC. could be it be MikroTik CRS310-1G-5S-4S+IN causing this problem?
regards,
Alex
The anser is: yes it could, but I think it's not the one you expect.
Once again:
does pppoe clients traffic sum to 2.4Gb?
is the 2.4Gb traffic somehow connected to 326 devices traffic?
does 310 show 2.4Gb output traffic towards 2116?
what happens if you bypass 310 connecting 326s to 2116?
does pppoe clients traffic sum to 2.4Gb?
No.
my CCR2116 directly feed arount 24 PPOE Client inside CCR2116 and feed 2 more router in Site 1 and Site 2 that handle PPOE users.
I have also Wireless Network and Hotspot all feed by CCR2116.
What "Connections" tab shows?
You have try to find the source of that traffic? Is it 2116 to 2116 one? LAN -> WAN, 2116 -> 310 one?
Any clues what it could be?