How much Support RB3011

How many requests does an RB3011 support, I have a network of approximately 3000 to 4000 users divided into subnets, for the central network I have an RB3011 that is not supporting the traffic the CPU is set to 80% and there are no rules in the firewall or NAT , everything is by static routes, is that the RB3011 does not support that amount or is something wrong in the configuration, everything is for forward without anything in the firewall, and the Interfaces enter ether1 by VLANs and exit through the ether2 where the servers are
rb3011hlg.jpg

use fast track on forward chain, established and connected traffic.

https://mikrotik.com/product/RB3011UiAS-RM#fndtn-testresults
this is some indication for you.

List your config (/export hide-sensitive compact) for more in depth feedback.
Some idea’s:

This my config, even when the CPU is at 40% the routerboard mising ping to any server connected to LAN
ruterboard.JPG
export.rsc (96 KB)

So:

  • no bridges/switches, all is routed through cpu (switch is only used for tagging)
  • there is use of queue simple
  • there is use of interface queues
  • there is mangling in place
  • be careful with “/ip proxy cache-on-disk=yes” it can bog down cpu with IO wait-states and kill the nand
  • using bgp & ospf which also taxes the cpu
  • connection tracking is enabled

There are some configuration inconsistencies (ex: fasttrack & simple queues) which need to be resolved. If you can disable firewall all the way it might be enough.

But overall, in my opinion the hardware is undersized for the job, CCR is probably a better match.

I change to a x86 intel xeon e5630 cpu with 2gb of ram and 3 network card pci express 1gb, but the traffic keeps is going down ever 10 or 20 min

  • you’re wan ip’s are fixed right? then you should be using src-nat instead of masquerade
  • do you propagate the dynamic client’s ip through dynamic routing? On /ip basis or by ranges? first one (/ip) could cause regular routing updates / sync on clients leaving / disconnecting

This is my Interface photo, and my config on the x86, there is no problem of CPU Load is something that is failling maybe is the config
Captura.JPG
Backup2019.rsc (105 KB)
I think in change the config general to all but i dont know if another method of routing is more efficient
PD: Sorry for my english

This is what I meant: https://mum.mikrotik.com/presentations/EU17/presentation_4058_1490948376.pdf
point 1: slide 23
point 2: slide 16

Already here I discovered the problem, are the servers of the games, that when I put them on the gateway 192.168.16.254 that is the IP of the Routerboard through the interface they start to lose packets pinging everything in the network even at same 192.168.16.254 that is by cable, it will be some problem in the configuration of the Routerboard, because if the servers I put static route for the clients of the network without putting gateway to him they do not give those failures of pins neither of packages.

The problem is that I do not have NAT in any side of the network everything works by routes to catch the IPs of the clients, in which the configuration could be improved to avoid that

in that case, have you this set?

/ip settings set rp-filter=strict

No, this option i dont have like that, i going to test and tell the results

Hi put this option but no results, the network remaing the same, with loss of packets, is another thing that provocate this failure