Is CRS or CSS the Better Choice for Small Business Networks?

Hi everyone,

I'm currently reviewing MikroTik switching options for a small office deployment, and I'm trying to decide whether a CRS series switch is worth the extra investment compared to a CSS model.

The network isn't particularly large—around 40 to 60 users—but reliability, VLAN support, and future scalability are important. At the same time, I don't want to overcomplicate the setup if a simpler switch can handle the workload just as well.

For those who have worked with both series, what has your real-world experience been?

Some of the things I'm considering are

  • Long-term reliability
  • VLAN configuration and management
  • PoE support (where applicable)
  • Switching performance under daily office traffic
  • Ease of maintenance

If you were building a network today for a growing small business, which series would you choose, and why?

I'd really appreciate hearing about real deployment experiences rather than just specifications.

Thanks!

My view, if you can afford it, always go for CRS unless you really want a managed switch and nothing more.
CSS runs SWOS and the difference between ROS and SWOS is even bigger then night and day IMHO.

I have at home CSS318, a couple of CSS610 deployed with customer (normal and POE version) but most other switches I use are CRS-line.
It's a lot easier if you can stay with the same ROS environment, SWOS is TOTALLY different.
Also, lots of things you can do with ROS which are simply not possible using SWOS.
Main thing for me already is ROMON. Forget about using that path with SWOS.
You can terminate VPN access or e.g. EOIP tunnel on ROS, not so on SWOS (you need another router then).
Updates are more frequent on ROS then SWOS (obviously also because the latter is so much simple/easier, but still ... ).
...

Performance-wise they are the same.
Reliability is something I haven't had any bad experience with.
If CSS device works, it works.

You will find a (large) "hole" in the Mikrotik range if you are looking for PoE switches.

There is a single 24 port:
https://mikrotik.com/product/crs328_24p_4s_rm

and a single 48 port model:
https://mikrotik.com/product/crs354_48p_4s_2q_rm
both CRS.

Or - if you prefer - the only CSS device with PoE out ports is the:
https://mikrotik.com/product/css610_8p_2s_in

For 40-60 users (intended as 40-60 ethernet connections/sockets) I would get two 48 port switches, so that you can add cables if needed and you have 100% or almost 100% redundancy, and this means CRS354 anyway (whether PoE or not depends on your needs).

SwitchOS has basic VLAN capability. It's basically what the hardware provides.

Switching performance is determined by the hardware, so noch differenced.

PoE is a hardware thing, so no differrence.

Features you may want:

  • Routing: RouterOS switches can do routing. And depending on the route and the switch type this can be hardware-offloaded, i.e. fast (no CPU load)
  • IEEE802.1X: Authentication on the switch level. Imagine an area accessible to visitors or the public. You don't want a visitor to plug in his notebook and scan your network, but you want to be able to use your own notebook for apresentation. "cleaning woman proof".
  • Logging: SwitchOS does no logging. If the switch reboots in the middle of the night you don't get a log entry. RouterOS does have internal logging and can do things like syslog.
  • Simple network tasks: RouterOS can do DHCP, DNS, Wireguard, NTP, and lots of other things. If you dont need then, turning them off does no harm.
  • CAPsMan: RouterOS devices can be used to manage Mikrotik Access points.

RouterOS is very capable. You may find that you need a feature in the future, and with RouterOS you have it.

PS: What PoE Power Class do you need? Most devices only support up to class 4 (PoE+,802.3at, 30W). Mikrotik has one switch capable of Power Class up to 8 (PoE++, 90W).

I agree with the others. If you decide on Mikrotik, inly buy the CRS version. If for no other reason then do it for the proper secure management interfaces.

I differ on this. Let routers route, and switches switch. RB5009, CRS305, CSS610 POE and 2x CSS318 here at this time. 10G backbone between switches and router, and POE powered AP's with CapsMan. All higher function on the far more capable RB5009 . . . fwiw . . .

So, to that end, if you only need a switch, CSS does the job fine with very few exceptions, and is far easier (albeit different) to config. (I have one CRS, and am running SwOs on it . . . ROS just didn't deem to be worth the bloat on a 10G backbone device.)

(And I see nothing in your list of requirememts that CSS won't do.)

Ultimately, port capacity may be more of a determining factor.

SwOS is imho the black sheep, updates are only provided a few times per year (if so at least). And SwOS is very limited, your hardware can more, but the "brain" is very smol with SwOS. ROS is far more flexible, you can create Netwatch-stuff and couple this with with SSH, like if some port goes down, SSH into some other device and do this and that... Impossible with SwOS. Or create daily backups and uplod (fetch) these with with ROS to a storage...

I would go for CRS with ROS. If you want a plain managed-switch, to be honest, other vendors have imho better options (more features than SwOS but not a universe like ROS). And stuff like Stacking is a rabbit-hole with Tiks, impossible or brainfucked as hell with nonsense like "MLAG"... You can see clearly, the main competence of Tik is routing, not switching imho.

I use Tik-SWs at home, beacuse they are cheap (got an CRS354-48P for 175 Euro second-hand). For my soul and my sanity, I would never ever in my live use them at work (I talk about switches - routers yes).

Run RouterOS on Your Switch.

That article pretty much confirms what Inhave been saying . . . . Most of that stuff isn't normally "switch" function, but rather router, so ifnyou want a router, thennROS for certain.

The security stuff is almost comical . . . If you let an unknown partynor packet get to your admin port, you already lost at least 80% of the fight. SwOs supports admin on a specified VLAN, which, if properly secured, pretty much negates most of those arguments. It's the difference between a purist mentality and a realist . . . .

And, while CLI is nice, the SwOs interface is so bonehead simple that it's hardly much of a loss . . .

Use what works, but I find the SwOs bashing almost comical. Where it works, it works damn well. (And I would expect the WinBox resource use bashers to feel the same here . . . )

It all comes down to what you want. CSS is a switch. Set it and forget it.

The CRS is for those who don't know what they want, want to fiddle with the tech and try various setups in their "home lab". Or for businesses who like to keep unified stock of devices and deploy them to customers as either switch or a router depends on the circumstances.

But to be honest, the CRS as concept is a niche product. You either need a switch or a router. You can not operate one device as two at the same time. Flipping between two modes will cost you dearly (downtime, and human labour). So, you may as well buy another device. And as routers, CRS devices are rather weak.

And how did CRS devices came about in the first place ? This is a good question, and here is my take on it:

Mikrotik is a full-cycle manufacturer - It designs and manufactures everything in house. It does R&D, rapid prototyping, final assembly and packaging. In order to do so Mikrotik must keep a stock of electronic components in house. Next, to control the end result, and (most critical) the quality of final products, you need to have a full control over the entire supply chain of electronic components.

Whether Mikrotik sends out to third parties (contract manufacturing), or operates its own assembly-lines (which it does), they will have to supply their own components. And they come on a tape in large reels.

Now, think about it: A reel of 16Mb Nand flash ICs would have 5000 of them on a single reel. Multiply it by a factor of x100(because there are hundreds of other components required).... And I am being conservative here in my estimates. So Mikrotik must keep 100's of Thousands of $ dollars worth of components (perhaps into millions of $ dollars). All of it sits on the shelf, and as we all know, the industry grows, and demands more and more memory, these 16Mb flash ICs are dead stock. So Mikrotik has to come up with an Idea to use these components...

This is how the entire class of devices called Cloud-Router Switches (CRS) came to life. It is out of necessity to put old components into use. So Mikrotik invented a new class of devices - this is how I think CRS line of products was born.

It is likely that Mikrotik not limiting the use of its production capacities to routers, switches and wireless equipment.

If they did we would continue to see routers/switches produced with 16Mb of flash storage for another 10 years which is dead niche. So Mikrotik would be stupid not to offer it's assembly lines to third parties - such as building electronics for drones used in Ukrainian drones, for example. Hopefully old stocks of electronic components will go up in flames.

So, my take on CRS devices - they don't make sense, and we shall see them disappear in the future, as old stocks are depleted.

Is that story based on fact or just your conjecture (what we would call hallucination if we were discussing AI)? I havnt't been using MikroTik long enought to make any claims about what inspired their product lines, but an excess of 16Mb NAND flash chips (2MB) would explain the current CSS line better than the current CRS line.

A glance at the Mikrotik:Hardware:Switches page shows 31 CRS, 9 CSS. A quick search suggests no CSS device provides 10G ethernet ports rather than SFP+ uplinks. CRS offers variety.

I think CRS is dominant and will stay for good reason. While there is a marginal difference in switch costs the principal factor in business is management and maintenance resources (labour). ROS covers both routing and switching, SWOS does not, and learning one OS is more efficient than learning two. If you were truly to have such a person as a dedicated "switch techie" then that is fine, teach them only the switch bits of ROS and declare the rest off-limits. It seems pretty unlikely that would happen.

For flexibility and whole of life costs in the network go ROS, i.e. CRS. Nothing is added by SWOS, much is subtracted.

If you know networking, SwOs should be no more than 10 mins once, even for the densest admin. (Not sure after months or years that I don't still have gaps in ROS, as well as the constant changes.) The concepts are similar, so I personally think thatbthe 1 vs 2 OS argument is irrelevant . . . Use what works best for the use case!

And you act like 10G on SFP+ only is a limitation? For some of us, crippled to copper only would be far more debilitating . . .

I don't get it . . .

What a novel thought.

As a matter of fact I do know large scale networking. In context of the opening post, I took the use case as a business, not a hardware device. None of my response is gainsaid.

As did . . . many years in the Fortune 50 and below.

Using a router when you need a switch is of questionable judgement.

Business or not, router functions on a switch are simply bloat and excess cost.

If you aren't sure, and you can afford the CRS go for that. Others have provided some reasons.

SwOS and ROS are two very different things, SwOS is simple and for what it does it does well, but it is really only a front end to setting up the switch chip registers, and not much else. It is the closest thing to a config free managed switch as possible, you don't even need to set a gateway address, it just responds to the mac address and ip address that the other end connected to. But because of that design decision, it can't establish any connections itself, so even firmware updates require assistence. As far as I know, none of the CSS models have console ports either, becausde they would be semi-useless, as the CSS doesn't have any command line commands, and you wouldn't be able to even do something as basic as updating firmware (that wasn't already downloaded to it).

If you are also using ROS routers, having switches that use the same basic management method is an advantage.

One thing that is nice about the CRS line is that if ROS is too intimidating, many of the models are dual-boot and can run either SwOS or ROS. So if you need to get something working while you are leaning ROS, you can run SwOS. However, if you start with SwOS, anything you have configured will be lost when you switch to ROS, it is like booting Linux vs Windows on a PC, what you configured on one is not converted to the other.

Do read tangent's Run RouterOS on Your Switch as it has a lot of the reasons he chooses to use ROS.

For an alternate view, see CRS326: RouterOS or SwOS? - #2 by k6ccc

Nobody asked that question.

If you need 802.1X, you have to run RouterOS as SwOS has no support for that.

No, it was just the core of the topic (giant "swooosh" as this flew over . . . . )

He specifically asked about two families of SWITCHES, not routers, directly indicating that switch function was all that is needed, and all the "features" folks mention in ROS are mainly router features . . .

True, but then again, I doubt many small businesses would bother with that.