Slow bandwidth and NAT RB3011

I have RB3011 set as more or less simple NAT router. Wan connectin is 150 Mbps. When accessed from the local network, speed gets to 65 - 80 Mbps max.

I tested link using btest to public btest server and it confirms there is 150 mbps. I also connected PC directly to the link, withut RB and then I have full 150 Mbps at the PC. So, link is ok.

On the RB, I have nothing fancy of the settings, some mangling rules and malicious connections detecting in firewall, and simple queue rules.

I tried to disable everything that I could but no change in speed.

I also checked CPU Load. It is 1% when there is no load, and goes up to 10% when i start speed test. So it also seems fine.

But for some reason, I get about half of the link speed.

I also tried to start speed test from the several local clients at the same time. Sum of the client’s speeds is again 65 - 80 Mbps.

Any hints why this may happen?

Please post your config
/export hide-sensitive file=anynameyouwish

# dec/28/2021 16:53:28 by RouterOS 6.48.5
#
# model = RouterBOARD 3011UiAS

/interface bridge
add name=bri-lan-cdama
add name=bri-lan-dv
add admin-mac=00:05:5D:D3:C8:9C auto-mac=no fast-forward=no mtu=1500 name=\
    bri-wan-sbb protocol-mode=none

/interface ethernet
set [ find default-name=ether1 ] advertise=\
    10M-half,10M-full,100M-half,100M-full,1000M-full name=eth1-sbb-wlnk
set [ find default-name=ether2 ] advertise=\
    10M-half,10M-full,100M-half,100M-full,1000M-full name=eth2
set [ find default-name=ether3 ] name=eth3-cdama-lan
set [ find default-name=ether4 ] name=eth4-cdama-11-llnk
set [ find default-name=ether5 ] name=eth5
set [ find default-name=ether6 ] name=eth6-dn-soba-wifi
set [ find default-name=ether7 ] advertise=\
    10M-half,10M-full,100M-half,100M-full,1000M-full name=eth7-sp-soba-wifi
set [ find default-name=ether8 ] name=eth8-sp-soba-tv
set [ find default-name=ether9 ] name=eth9-rsoba-switch
set [ find default-name=ether10 ] advertise=\
    10M-half,10M-full,100M-half,100M-full,1000M-full name=eth10

/interface list
add exclude=dynamic name=discover
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik

/ip pool
add name=dhcp_server ranges=10.16.0.200-10.16.0.254
add name=cdama.dv-pool ranges=10.16.1.101-10.16.1.151
add name=cdama.lan1-pool ranges=10.16.6.81-10.16.6.94

/ip dhcp-server
add add-arp=yes address-pool=cdama.dv-pool always-broadcast=yes disabled=no \
    interface=bri-lan-dv lease-time=5m name=cdama-dv-dhcp
add address-pool=cdama.lan1-pool always-broadcast=yes disabled=no interface=\
    bri-lan-cdama name=cdama.lan1-pool

/queue simple
add disabled=yes max-limit=1G/1G name=#SBB target=bri-wan-sbb
add disabled=yes max-limit=100M/100M name=queue1 target=eth2
add disabled=yes max-limit=128k/32k name=adsl-p2p parent=#SBB

/queue interface
set eth1-sbb-wlnk queue=ethernet-default
set eth2 queue=ethernet-default

/queue simple
add dst=bri-wan-sbb max-limit=1G/1G name=#WAN queue=default/default target=""
add max-limit=1G/1G name="DV [LS]" parent=#WAN priority=2/2 queue=\
    default/default target=10.16.1.0/24 total-priority=2 total-queue=\
    ethernet-default

add dst=eth7-sp-soba-wifi max-limit=1G/1G name=#LNK-CDAMA-11 queue=\
    default/default target="" total-queue=ethernet-default
add dst=eth2 max-limit=1G/1G name=#LNK-CDAMA-21 queue=default/default target=\
    "" total-queue=ethernet-default
add dst=bri-wan-sbb max-limit=1M/1M name=everything-else queue=\
    default/default target="" total-queue=default
/system logging action
set 0 memory-lines=100
set 1 disk-lines-per-file=100
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
    sword,web,sniff,sensitive,api,romon,dude,tikapp"
/dude
set enabled=yes
/interface bridge port
add bridge=bri-wan-sbb interface=eth1-sbb-wlnk
add bridge=bri-lan-dv interface=eth6-dn-soba-wifi
add bridge=bri-lan-dv interface=eth8-sp-soba-tv
add bridge=bri-lan-dv interface=eth9-rsoba-switch
add bridge=bri-lan-dv interface=eth10
add bridge=bri-lan-dv interface=eth7-sp-soba-wifi
add bridge=bri-lan-cdama interface=eth3-cdama-lan
/ip firewall connection tracking
set generic-timeout=1m icmp-timeout=1m tcp-close-timeout=1m \
    tcp-close-wait-timeout=1m tcp-established-timeout=1m \
    tcp-fin-wait-timeout=1m tcp-last-ack-timeout=30s \
    tcp-syn-received-timeout=1m tcp-syn-sent-timeout=1m \
    tcp-time-wait-timeout=1m udp-stream-timeout=1m udp-timeout=1m
/ip neighbor discovery-settings
set discover-interface-list=all
/ip settings
set rp-filter=loose
/interface detect-internet
set detect-interface-list=all
/interface list member
add interface=eth2 list=discover
/interface pptp-server server
set default-profile=default enabled=yes max-mru=1460 max-mtu=1460
/ip address
add address=10.16.6.34/29 comment="stari lan ruter" disabled=yes interface=\
    eth2 network=10.16.6.32
add address=10.16.2.6/30 comment=wiif-krov interface=eth4-cdama-11-llnk \
    network=10.16.2.4
add address=89.216.114.92/26 disabled=yes interface=bri-wan-sbb network=\
    89.216.114.64
add address=10.16.0.1/24 comment=server-lan interface=bri-lan-dv network=\
    10.16.0.0
add address=10.16.1.1/24 comment=dv-lan interface=bri-lan-dv network=\
    10.16.1.0
add address=10.16.6.65/27 interface=bri-lan-cdama network=10.16.6.64
add address=192.168.100.9/24 interface=bri-wan-sbb network=192.168.100.0
/ip dhcp-client
add default-route-distance=2 disabled=no interface=bri-wan-sbb use-peer-dns=\
    no use-peer-ntp=no
add default-route-distance=2 interface=eth1-sbb-wlnk use-peer-dns=no \
    use-peer-ntp=no
/ip dhcp-server config
set store-leases-disk=immediately
add address=10.16.6.78 comment="Precistac vazduha Xiaomi" mac-address=\
    04:CF:8C:AB:09:0C server=cdama.lan1-pool
/ip dhcp-server network
add address=10.16.0.0/24 dns-server=10.16.0.1 gateway=10.16.0.1
add address=10.16.1.0/24 dns-server=10.16.1.1 gateway=10.16.1.1
add address=10.16.6.64/27 dns-server=10.16.6.65 gateway=10.16.6.65
/ip dns
set allow-remote-requests=yes cache-size=4096KiB servers=1.1.1.1,1.0.0.1
/ip dns static
add address=10.16.0.1 name=lan-dns

/ip firewall filter
add action=drop chain=input comment="Drop invalid connections" \
    connection-state=invalid disabled=yes log-prefix=\
    "Dropped invalid connection"
add action=drop chain=forward comment="Drop invalid connections" \
    connection-state=invalid disabled=yes log-prefix=\
    "Dropped invalid connection"
add action=accept chain=input dst-port=22 in-interface=bri-wan-sbb protocol=\
    tcp src-address-list=allow_ssh
add action=add-src-to-address-list address-list=ssh_conn_level_0 \
    address-list-timeout=1m chain=input connection-state=new dst-port=22 \
    protocol=tcp
add action=add-src-to-address-list address-list=ssh_conn_level_1 \
    address-list-timeout=1m chain=input connection-state=new dst-port=22 \
    protocol=tcp src-address-list=ssh_conn_level_0
add action=add-src-to-address-list address-list=ssh_conn_level_2 \
    address-list-timeout=1h10m chain=input connection-state=new dst-port=22 \
    protocol=tcp src-address-list=ssh_conn_level_1
add action=drop chain=input connection-state=new dst-port=22 log=yes \
    log-prefix="Dropped brute force to SSL" protocol=tcp src-address-list=\
    ssh_conn_level_2
add action=drop chain=input comment="block public DNS" dst-port=53 \
    in-interface=bri-wan-sbb log=yes protocol=tcp
add action=drop chain=input comment="block public DNS" dst-port=53 \
    in-interface=bri-wan-sbb log=yes protocol=udp
add action=reject chain=input comment="Drop banned addresses by list" \
    log-prefix="banned by list" reject-with=icmp-host-prohibited \
    src-address-list=banned-addresses
add action=reject chain=forward comment="Drop banned addresses by list" \
    log-prefix="banned by list" reject-with=icmp-host-prohibited \
    src-address-list=banned-addresses
add action=add-src-to-address-list address-list=new_connections \
    address-list-timeout=none-dynamic chain=input comment=\
    "Detect new connections" connection-state=new disabled=yes in-interface=\
    bri-wan-sbb nth=2,1
add action=log chain=input disabled=yes log=yes log-prefix=\
    "in new connections list" src-address-list=new_connections
add action=accept chain=input comment="Allow established connections" \
    connection-state=established
add action=accept chain=input comment="Allow related connections" \
    connection-state=related
add action=accept chain=input comment="Allow UDP" protocol=udp
add action=accept chain=input comment="Allow ICMP Ping" protocol=icmp
add action=accept chain=input comment="Allow access from address list" \
    src-address-list=allow_access_from
add action=accept chain=input comment="Allow access to MT" src-address-list=\
    access_to_mt
add action=accept chain=forward dst-port=25 in-interface=bri-wan-sbb \
    protocol=tcp
add action=accept chain=forward dst-port=25 log=yes log-prefix=\
    "Allowed outgoing SMTP" out-interface=bri-wan-sbb protocol=tcp \
    src-address-list=all-smtp-allowed
add action=drop chain=forward comment=\
    "Drop outgoing SMTP not allowed by list" dst-port=25 log=yes log-prefix=\
    "Drop outgoing SMTP not allowed by list" out-interface=bri-wan-sbb \
    protocol=tcp src-address-list=!all-smtp-allowed
add action=drop chain=forward comment="Drop all other outgoing SMTP" \
    disabled=yes dst-port=25 log=yes log-prefix=\
    "Drop all other outgoing SMTP" protocol=tcp
add action=drop chain=forward comment="Microsoft Networking is disallowed" \
    dst-port=135-139,445 protocol=tcp
add action=drop chain=forward dst-port=135-139,445 protocol=udp
add action=accept chain=forward in-interface=bri-wan-sbb
add action=accept chain=forward out-interface=bri-wan-sbb
add action=accept chain=forward dst-address-list=dst_allowed_to_all
add action=accept chain=forward src-address-list=dst_allowed_to_all
add action=accept chain=forward dst-address-list=licenced
add action=accept chain=forward comment="Allow connections to allowed sites" \
    dst-address-list=dst_allowed_to_all
add action=log chain=forward comment="Drop everything else" log-prefix=\
    "drop other forward"
add action=drop chain=forward

/ip firewall mangle

/ip firewall nat
add action=masquerade chain=srcnat comment="privremena maskarada svega" \
    log-prefix=masquarade out-interface=bri-wan-sbb
add action=dst-nat chain=dstnat dst-address-list=dst_nat dst-port=25,110,143 \
    in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=SSL dst-address-list=dst_nat \
    dst-port=443,465,993,995,587 in-interface=bri-wan-sbb protocol=tcp \
    to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=DC++ dst-address-list=dst_nat \
    dst-port=411 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.10
add action=dst-nat chain=dstnat comment="HTTP to 10.16.0.11" \
    dst-address-list=dst_nat dst-port=80 in-interface=bri-wan-sbb log-prefix=\
    www protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="Chia to 10.16.0.11" \
    dst-address-list=dst_nat dst-port=8444 in-interface=bri-wan-sbb \
    log-prefix=www protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="FTP/SFTP  to 10.16.0.11" \
    dst-address-list=dst_nat dst-port=21,990 in-interface=bri-wan-sbb \
    protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment="FTP passive ports to 10.16.0.11" \
    dst-address-list=dst_nat dst-port=2221-2231 in-interface=bri-wan-sbb \
    protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=HTTP dst-address-list=dst_nat \
    dst-port=88 in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10 \
    to-ports=80
add action=dst-nat chain=dstnat comment=cluster.uzice.net dst-address-list=\
    dst_nat dst-port=7373 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.10
add action=dst-nat chain=dstnat comment=cluster.uzice.net dst-address-list=\
    dst_nat dst-port=3608 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.10
add action=dst-nat chain=dstnat comment=HTTP dst-address-list=dst_nat \
    dst-port=90 in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.10 \
    to-ports=90
add action=dst-nat chain=dstnat comment=SVN dst-address-list=dst_nat \
    dst-port=8443 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.10
add action=dst-nat chain=dstnat comment=CVS dst-port=2401 in-interface=\
    bri-wan-sbb protocol=tcp to-addresses=10.16.1.10
add action=dst-nat chain=dstnat comment=eQSO dst-address-list=dst_nat \
    dst-port=10024 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
    dst_nat dst-port=5060 in-interface=bri-wan-sbb protocol=tcp to-addresses=\
    10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
    dst_nat dst-port=5060 in-interface=bri-wan-sbb protocol=udp to-addresses=\
    10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
    dst_nat dst-port=4000-4019 in-interface=bri-wan-sbb protocol=udp \
    to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="VOIP HAM RADIO" dst-address-list=\
    dst_nat dst-port=4000-4019 in-interface=bri-wan-sbb protocol=tcp \
    to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="AnyDesk to 10.16.1.11" \
    dst-address-list=dst_nat dst-port=7070 in-interface=bri-wan-sbb log=yes \
    protocol=tcp to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="AnyDesk to 10.16.0.11" \
    dst-address-list=dst_nat dst-port=7071 in-interface=bri-wan-sbb log=yes \
    protocol=tcp to-addresses=10.16.0.11
add action=dst-nat chain=dstnat comment="EchoLink Pedja" dst-address-list=\
    dst_nat dst-port=5198,5199 in-interface=bri-wan-sbb protocol=udp \
    to-addresses=10.16.1.11
add action=dst-nat chain=dstnat comment="Skype to 10.16.1.11" dst-port=1025 \
    in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.11 to-ports=\
    1024
add action=dst-nat chain=dstnat comment=\
    "Port 31000 dst-nat to 10.16.1.11 (BasCelik)" dst-port=31000 \
    in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.1.11 to-ports=\
    31000
add action=dst-nat chain=dstnat comment="Winbox to 10.16.0.1" dst-port=8293 \
    in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.0.1 to-ports=\
    8292
add action=dst-nat chain=dstnat comment="Winbox to 10.16.2.5" dst-port=8294 \
    in-interface=bri-wan-sbb protocol=tcp to-addresses=10.16.2.5 to-ports=\
    8291
add action=dst-nat chain=dstnat comment=IPIP dst-address-list=dst_nat \
    in-interface=bri-wan-sbb protocol=ipip to-addresses=10.16.6.17
/ip route
add distance=5 gateway=89.216.114.65 routing-mark=to-sbb
add distance=2 gateway=89.216.114.65
add distance=1 dst-address=10.16.0.0/16 gateway=10.16.6.33
add distance=1 dst-address=10.31.0.0/16 gateway=10.16.6.33 scope=255
add distance=1 dst-address=10.50.10.0/24 gateway=eth2 scope=255
add distance=1 dst-address=192.168.100.0/24 gateway=bri-wan-sbb pref-src=\
    192.168.100.10 scope=10

/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote

/ipv6 nd
set [ find default=yes ] advertise-dns=no

/routing ospf network
add area=backbone network=10.16.0.0/16
/system identity
set name=IDR
/system logging
add topics=watchdog
add topics=e-mail
add topics=script
add prefix=pptp topics=pptp
add topics=account

/system ntp client
set enabled=yes primary-ntp=109.245.222.66 secondary-ntp=217.24.20.5
/system ntp server
set broadcast=yes enabled=yes multicast=yes
/system package update
set channel=long-term

(1) STRUCTURE is inconsistent
a. so three POOLS , assuming for two bridges and ???
b. so why only two DHCP servers (one for each bridge).
c. So why back to three DCHP server networks ???


(3) Bridge ports 6-10 are on one bridge, Wan(ether1) on its own bridge, Ether3 on its own bridge.

so that leaves ether 2,4,5 in the dark

Then we have more confusion
(4) SEVEN IP Addresses WTF ??
a. Okay I see an address for ether2 that sorta could be associated with dhcp server un named…
b. Okay I see an address for ether4 that is unique.
c. Okay I see an address for the WAN connection bridge
d. Okay I see an address for one LAN bridge bri-lan-cdama
d. Uh-Oh I see two addresses for ONE LAN BRIDGE
add address=10.16.0.1/24 comment=server-lan interface=bri-lan-dv network=
10.16.0.0
add address=10.16.1.1/24 comment=dv-lan interface=bri-lan-dv network=
10.16.1.0
e. SEE ANOTHER WAN bridge address ??? Okay the one at c. is disabled…

(5) Why use the standard SSH port 22 and not something like 14220

(6) Egads, extremely messy firewall rules… too tired to even to know where to begin.
SMTP should not be something handled in firewall rules… and further a forward chain rule to allow port 25 full access to the ROUTER from external??

In Summary,
You should not clearly the USE Cases / functionality you wish to have without talking about the config!!

  • I want to run my own mail server
  • I want to control bandwidth usage or access to the WAN, within the LAN
  • I want groups of users/devices to be able to X and Y but not do A and B
  • I want individual users/devices to be able to D and E but not G and H
  • others

and revert back to default firewall rules and start fresh. way to noisy to fix up.

I believe all those things are irrelevant to the throughput problem I have.
I see no issue with two separate IP ranges in local network, or that I have SMTP server in local network.

As I said I did test with disabling all those things.

Yes, my plan is to get another routerboard and do basic setup and test further more. I just cannot do that on this working router as it needs to handle existing network.

I hoped someone would have an idea what could cause throughput limit so I can try something without getting another board.