Hello,
I have i mikrotik box with average 30~40% load . when i enable following rules , its load cames 100% and everything stops working . i have contacted with support and they said
Everything seems fine except that your configuration is very huge, and you need to hire a consultant to do some optimizations, there is room for improvement. I also suggest to upgrade to some multicore Intel i7 machine, as you are pushing the capability of Pentium4.
As i am an experienced mikrotik user i think these 20 lines of simple configuration should not be so heavy as 60~70% . and this system is very stable and i can not risk to change this with a new multi core because i have very bad experience with core 2 quad .
Please help me to optimize the following config. all address lists are dynamic so should use separate rules for each one .
32 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list64 connection-limit=50,32
33 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list128 connection-limit=50,32
34 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list192 connection-limit=50,32
35 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list256 connection-limit=50,32
36 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list384 connection-limit=50,32
37 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list64_1 connection-limit=50,32
38 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list128_1 connection-limit=50,32
39 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list192_1 connection-limit=50,32
40 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list256_1 connection-limit=50,32
41 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list384_1 connection-limit=50,32
42 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_list512_1 connection-limit=50,32
43 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP1 connection-limit=50,32
44 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP2 connection-limit=50,32
45 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP3 connection-limit=50,32
46 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP4 connection-limit=50,32
47 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP5 connection-limit=50,32
48 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP6 connection-limit=50,32
49 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP7 connection-limit=50,32
50 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP8 connection-limit=50,32
51 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP9 connection-limit=50,32
52 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP10 connection-limit=50,32
53 X ;;; Limit Connections
chain=forward action=drop tcp-flags=syn protocol=tcp src-address-list=dynamic_address_listP11 connection-limit=50,32