Problem loading websites, dns seems ok, ROS 5.14

Hello everyone,

I have a problem since a few days, I can’t really say for sure what changes have been done or not. We had a downtime of one of our uplinks and had to move several PPPoE Clients to another routerboard and after moving them back to the old one, some problems came up.
It’s about a RB1100 acting as a pppoe-server with ROS 5.14. I had to route some clients to that board after their original uplink was broken. When I moved them back, some clients reported problems on the RB1100. Some websites (not all) load very slowly or even not at all. Usually I get a quick DNS resolve, the header of the website is shown pretty fast, but loading the content, especially pictures, often fails or takes forever. Sometimes reloading the website a few times helps, but not always.
I checked DNS cache settings, but since some of the clients use own DNS settings not using the RB1100 cache, I doubt that’s the cause.
I checked the MTU size and it is left unchanged. MSS sizes are dynamically reduced by 40bytes similar as described here: http://wiki.mikrotik.com/wiki/Manual:RouterOS_FAQ (unter I cannot browse some sites).
Ping times are fine, no packet losses.

To be honest, I set this scenario up quite some time ago and I’m not 100% sure about all the settings right now, it worked fine so far and the collegue who helped me there is not around anymore.
Any ideas what options/settings to check?

No one got any idea?

If you are unsure how your network is setup, then I would suggest you post a diagram of your network with a much info as possible (omit any passwords) then users here maybe able to offer advice.

Try to switch the port connected to customer with problem. I have had this error on some 1100 and 1200. It seems like ether 8, rarly have some issues.. I dont use port 10 -13. Try using just switchgroup 1.

Also try checking your cables, and post settings (speed)

how about interface queues?

I also sometimes see problem with dns. If a client try to resolve a host, using mikrotik as dns server and the dns is pointing to a cname on www, rather than a " full hostname", its problems resolving it.