[Help] Transparent bridge and ip firewall filter *very* slow

:cry:

Disclaimer: I probably have no clue what I’m doing…

I’m at a complete loss. For years I’ve run a bridging Linux firewall, actually, several of them. No problems.

Recently I built several new Mikrotik boxes w/ Routerboard 44 cards for a bunch of network changes going on in our college. Right now, these consist of nothing but two active interfaces, bridged, with one or two dozen rules in “ip firewall filter”. The only configuration change beyond the defaults for the bridge is to turn on STP.

The boxes are horribly slow - running at maybe 5-6Mbit second on 100Mbit gear - even over very short cable runs. Things are looking very dire.

The switches feeding these boxes are Cisco gear and yes, syncing appeared to be a problem. The group that manages the switches, however, forced the interfaces to 100 Full, and things are even worse… it doesn’t make any difference if I force the Mikrotik interfaces to 100F or not. (Well, it may make an tiny tiny tiny different, or it might just be random fluxuations in speed).

If I start playing with settings… moving things to 100 half on the Mikrotik, the bandwidth-test numbers go up, but performance is still abysmal. I don’t know if this makes any difference, but the UDP test results are much higher than the TCP numbers.

Please. Any advice would be appreciated. This has turned a simple move into a disaster. If anyone has any thoughts on how to remedy or troubleshoot the problem, please let me know… and please be specific with where to look in the Mikrotik setting heirarchy. Email appreciated.

Thank you for your time,
John Ray
ray.30@cfaes.osu.edu

Have you tried the onboard Ethernet NIC’s? We noticed a speed problem with the Routerboard 44 ports when running 2.9.26. An upgrade to 2.8.27 seemed to fix it. Of course, there was no mention of a problem or a fix in the Changelog.