Is CRS or CSS the Better Choice for Small Business Networks?

Seriously tadawson, you are missing the point, illustrated by the above quotes in which you contradict yourself. The question is CRS or CSS, which leads directly to the value of using ROS on your switches (as I do on all of mine in switch mode).

My original point in any event, as also commented by others, was regarding randomwalk's speculations about the basis for Mikrotik's switch offerings. CRS switches dominate their offering in this space, and are the obvious choice for a small business ("40-60 users ... growing") unless you are keen to save pennies on the capital purchase.

Are you certain that rosiecharles is a "He"? :slight_smile:

Nope! Full bozo yet again. . .

The discussion of two families of switches clearly excluded routers, effectively negating a use case for ROS on a switch platform (the CRS).

It might look like a switch, but put ROS on a CRS and you have also made it a potential router (albeit not a good one).

And ICGAF about pronouns. Perhaps I will refer to all as "it" to appease those so aflicted with such irrelevancies . . . :slight_smile:

Regarding routers, as I said earlier,

You alone said

and still nobody else proposed the notion.

So? Is that a horror? ROS has switch mode which enables it perfectly as a switch, with benefits. See also many comments by other experienced users in this thread. Your comment reinforces my point that you appear to be discussing something other than the question. You are also trying to resort to petty insults. I commend to you a quiet walk. :slight_smile:

Yes, ROS can switch . . . with massive code bloat for the task . . . an extra processor (or more processor) needed to run it, and likely more power drawn . . . . to do almost nothing that SwOs can't already do, just as fast, for lower cost.

And the instant someone proposed ROS on a switch, they proposed EXACTLY that notion!

And "with benefits"? Makes about as much sense as putting a V8 engine in a car, but only running on 4, while paying to haul all the extra weight and complexity around . . .

I still don't see a valid point . . . And no "petty insults" . . . just a very poor tolerance for BS and cluelessness. Some folks just love to crap on SwOs, and still havent heard a reason other than basically being too lazy to learn a second interface . . .

Who crapped on SWOS?

Switching is at hardware level, performance the same. "Code bloat" is like complaining about the paint colour, except that in this case there are benefits from using ROS should you choose to do so on a CRS device, unavailable on a CSS device, and that was rosiecharles' original question widely answered above in general favour of the CRS option.

You refer to Mikrotik, who provide that option on 78% of their advertised switches, and whose provision of that option has been supported by the majority of experienced users posting on this thread. Chide Mikrotik and those users for their "BS and cluelessness".

Peeps, play ball, not man.

You can discuss ROS / SWOS as much as you want but I do not want to see it become personal.
OK ?

For me the biggest reason to stick as much as I can to ROS is the accessibility from remote and the fact I can ROMON in almost everywhere from my clients network. Can't do that when the target is a SWOS device.
I know my way around SWOS for what I need it to do and yes it's pretty simple but I still prefer ROS a lot more.

The switch I use the most with my client is CRS326. It exists in swos-only version as well.
But for 40$ list-price difference, I will gladly take ROS every time.
Already happened a couple of times I had to enable some router functions on such a switch.
Like enabling a EOIP or Wireguard tunnel to a central location (and then ROMON using that tunnel).
Could not have done that with the SWOS version.

And it would have cost me several times 40$ otherwise to go on site to fix some things or replace the device.

I adjusted the definition in my dictionary:
Mikrotikish<->English conversion table/dictionary

Mikrotikish Meaning in Mikrotik world Meaning in real world English
CRS Cloud Router Switch a good switch with marginal router capabilities, the Cloud and Router in the name have been added by the marketing department. switch, like the CSS, only better
CSS Cloud Smart Switch a switch with low resources, using SwOS or SwOS lite instead of RouterOS, the Cloud and Smart in the name have been added by the marketing department. low cost switch for the masses

Who crapped on SwOs????

Are we reading the same thread?

Everyone saying not to use it, even where it fits the need 100%!

This sounds like 100% covered by CSS (SwOs). Isn't it?

I guess we all design networks differently. I access the management VLAN via VPN to router "fronting" the location, and can get to either trivially from anywhere.

On cost, the case I was looking at, CRS vs CSS was over 2x the cost ($120 delta) to add features I would never use, so it got a firm "no". On my CRS305, SwOs just seemed better to me (despite "intimacy" with ROS on my routers and AP's). For jusr $40, I would have considered CRS as well (but likely run SwOs on it).

And Re: Mikrotik offering ROS on switches, sure. But was that for marketing reasons, for the small guy who wants to do everything in one place (albeing sub optimally) or ??? As noted prior, the OP was considering CSS, which screamed to me that he had no need for that feature set.

I also find it hyterical how on the WB4 thread, the biggest gripe is code bloat and resource use, and here, on almost infinitely more limited devices, folks are saying it doesn't matter. Sure, switching is chip based, but ROS (and most of it's additional features) clearly are not. I kindly suggest that the arguments are reversed . . . . it's vastly more critical in smaller, unexpandable devices. (Then again, I regard switches as marginally intelligent wire, and little more . . . the router is the "brain" of the operation in my networks, and feature/function centralizes in that one place.)

In any case, I think I've made my point, so the bashing can stop now . . .

My point from the beginning . . . :slight_smile:

The biggest part of the ISP routers are not under my control (33 sites) so I can not simply VPN in via the router.
Hence my need to have "something" capable to use in case that ISP MPLS borks out.

I'm an ISP and have run small offices in years past. Unless a CSS/SwOS-only device offers features that a CRS does not, I go CRS every time, particularly the 300 series. I have a couple CSS's; most are sitting on the shelf now. I pull them out when I need something for a lab or other temporary setup.

Maybe, if you're doing set-it-and-forget it, and never going to go back to that switch in the closet that runs a bunch of PC's, a CSS will be sufficient. SwOS can do VLAN tagging and basic port counters, maybe some rate-limiting, but otherwise it's pretty boring and feature-limited. And for many use cases, that's fine.

However, if you're frequently getting in to troubleshoot things, or change settings because of people's needs, or plan to upgrade things, etc. RouterOS is has much more in the way of flexibility and reporting, and RouterOS only runs on the CRS series.

If you want MLAG, VXLAN, MVRP, ACL's, and better remote management, RouterOS is the way to go. Personally, I use a lot of CRS300's as routers, too, with L3HW offload. Most of them can route about 800M-1000M with the onboard CPU if I have to disable L3HW offload, which is enough at most of my sites. Otherwise, the CPU's twiddling its thumbs, handling OSPF & BGP while the ASIC routes + switches all the traffic at line rate. All those saying they're not good routers need to add caveats: they're fine for routing, not so powerful at CPU-laden jobs.

The other thing to consider is that devices like switches and routers are like Legos. You put it in and use it for a while at one place, and if you need to upgrade or swap it, you can use it elsewhere. If you spend a little extra for the functionality and capability, you now have a more flexible/valuable Lego.

Besides the aforementioned features, consistency in management is why I run RouterOS on everything that can do both.

It was a speculative, but an educated guess coming from a bit of experience. The 16Mb flash chips was taken as an example, so you may as well substitute it with fill-in-the-blank line. Some time ago I had a role in the manufacturing of high temperature electronics for Oil and Gas industry with our electronics assemblies designed for 200C+ temperature range. It required a lot of testing, with components hand-picked from specific manufacturers. Let's say a design specifies Vishay or Panasonic SMT resistors, and these could not be substituted for anything else, but once the final PCB assembly is populated with components you will not know the difference what was actually mounted on the PCB, so the supply chain is critical. And making electronics to 200C+ operating temperatures stressed not only the components, or the PCB substrate material, but every other part of the business, incl. the supply chain. As an example, we would use Arlon polyimide instead of FR4 for PCBs. For a non-electronic components the design would call MIL-Specs, and we used a lot of materials used by the military. Another example, in our product is we used a 5VDC, 500mA linear voltage regulator (HTPLREG05) in a gold plated package priced at US $350 a piece. So, the Honeywell Aerospace (which was still manufacturing it back in 2015) had sent their sales team to out facility and twisted our arms to sign the contract. We had to commit a certain purchase volume of these each quarter. Shortly after the contract was signed, climate change policies (Hello Greta :slight_smile:) killed investments in Oil&Gas industry, and the demand for our products evaporated as we kept buying the shipments of these expensive parts and putting them on the shelf basically.

As Mike Tyson said: "Everyone has a plan until they get punched in the face".

And this is when, I think, marketing departments begin inventing new names for same old products. An excess supply of LCD screens? Apple offered a new form-factor and called it a 'Tablet'. This threatened the laptop market. Lenovo responded by introducing 2-in-1 convertible laptop and called it a "Yoga Tablet".

So, yes my post was speculative, and while the exact reasons behind CRS line of products are unknown, CRS are good switches, but mediocre as Routers.

From the consumer perception and sentiment point of view, it would help to decouple the strengths of CRS switches from CRS weaknesses as router devices.

I think the CSS product line and SwOS was launched to have a foot in the entry-level space of switches (where you usually have Netgear, D-Link, TP-Link, etc.) with simplified management. And the small footprint makes it possible to run within the Switch ASIC (that sometimes have a small general purpose CPU) as many of those vendors usually do.

But I would say that CSS is unfortunally tied to home or very-small office usage. For an enterprise or operator that has some kind of bare minimum IT-security baseline, single-user, non-encrypted, non-logged, non-backup is simply a no go. I would prefer if the could be managed from a adjacent RouterOS device at least.

Sounds like a call for "SwitchMan" from here? :slight_smile:

And what do you mean by "non backup" RE: SwOs?

There have been numerous tools over the years doing full network (IP as well as SAN) management. I have not looked recently, but the ones I had seen all seemed to have died . . . It's a daunting task unless single platform, and in that regard, ROS as a consistent component across the brand would make doing this on MikroTik gear far easier.

It would be really nice if a SwOS-device would be manageable from a RouterOS-device, via a sub-menu of some kind.

Sorry, I realised that there is a backup import/export. It's however binary and not editable.

We use Ansible for mange and backup devices. No SwitchOS support there unfortunally.

Thanks for the clarification. I guess there is a fine distinction between "config export" and "backup" . . . Thinking back through all the years I can't recall a clear text actual named "backup" on anything, but, but the config export can be nice (I just wish that they would make it portable! Hard to build a replacement device for a failed unit with a hardware specific backup . . . but there are other topics for that.)

It's not as much "best practice" any more (seems like folks just throw everything on the internet, and then actually seem amazed when they get hacked), but I honestly feel that the methodology of private admin networks with zero outside access provides a better primary layer of security than any https, ssh (or whatever). If an attacker can get to the port, there is always the possibility that the password was leaked by a human, and then you have nothing. Strong passwords (my "important" ones are 30+ characters and symbols ... I've even used control characters at times)coupled with private networks with restricted access give far better security, and also a chance to catch things at the early layers before there is any risk.

(The major institution where I currently manage many of the Tier-1 high risk systems does this . . . The servers are on a private, isolated network with only the required application ports mapped/translated by an F5. Zero certs used on the servers - all certs/encryptions are handled on the F5 for easier management and access control. (http to the F5, https to the users). Admin access requires being on a specific network (and here is the one thing a CSS won't do - we have all ports MAC locked to a specific device), and then running a VPN to the server specific network. Typically only 2 or 3 users with access to any system, but often with a common login. External access is more challenging . . . VPN (DUO challenged) to the system on the allowed network (specific VPN login ... "general" VPN won't get you there), login to it, a second VPN (again DUO challenged) to the server network, different login to the server there. 4 layers . . . works well. Put a device behind that and even if you used telnet, still secure. This has never failed to pass security audits done by external agencies as well ... it's solid.)

Most of the Enterprise admin tools also require a similar level of complexity to access.

Granted, more complex than what most can/will do, but similar to what I do even at home. Admin is on a non-routed VLAN, and the SwOs devices are restricted to that VLAN, and no ports are directly exposed to that VLAN. External access is VPN in, login to system with VLAN access, and then login to the switch on the isolated network. You can't capture passwords from a network you can't see, and any external access is already encrypted.

FWIW . . . (and possibly showing my age . . . )

Modern enterprise IT-security policies dictates encryption everywhere, signed certificates and multifactor logins for everything. There is no "safe" VLANs or "trusted" IP-ranges. Zero-trust doctrine all the way.

The same enterprise guys who go "all in" on cloud subscriptions. :person_shrugging: