RB450G slowly degrading

I got an RB450G about a year ago, in last few month I’ve seen a huge decline in performance, though countermeasures were deployed but now still not able get full bandwidth. Without changes on configuration, with(-out) upgrading to release/rc version firmware. I was able to get 250Mbps+ back in June, but starting from this August, I can only reach 100Mbps. I tried to remove most of the firewall rules, and it barely reached 200Mbps and capped.

Does that mean I will have to get a new Router?

Is the cpu maxed? What profile says during the capping traffic? Aren’t you a part of dns amplification attack? Have you tried fasttrack?

Yes, CPU is maxed at 800Mhz, firewall uses most of CPU at 40%, and I’m using fast-track no significant improvements.
As for amplication attacks, no, I’m not opening DNS/NTP to the public, and my IP address is dynamic.

Plus, I added a cooling fan and blow dust every week. (AQI suffers in Beijing.)

Maybe I’m getting a 3011 soon, since I’ve upgraded my home network to 10GbE.

Hard to guess. Generally it is advisable to update ros and firmware then recheck your config and finetune or adapt it for new version capabilities. What rest uses cpu when it is at 100% with firewall at 40%? Anyway such high firewall values may mean that the fasttrack is not involved much.