Slow transfer speeds on LAN

I am currently running a RB3011UiAS that is connected into a CSS326-24G-2S+ for some of the switching. I have a semi complicated environment running a number of different subnets and VLANs. But in this case I am simply trying to transfer a file from 10.0.0.11 into 10.0.0.9. The transfer rate starts at roughly 120 - 95 mb/s before slowing creeping down and maintaining somewhere near 12 mb/s. The transfer will also pause at times before starting up again

I noticed a similar problem on a different transfer between my 10.X subnet and a server on the 30.X subnet range. In this case each individual transfer completely quickly although they were much smaller in size 200 mb files vs. 197 gb. But again they paused between each file for a significant period of time before eventually proceeding. This happened rather recently.

I have provided an export of my system settings:

  MMM      MMM       KKK                          TTTTTTTTTTT      KKK
  MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK
  MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK
  MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK
  MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK
  MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK

  MikroTik RouterOS 6.44.5 (c) 1999-2019       http://www.mikrotik.com/

[?]             Gives the list of available commands
command [?]     Gives help on the command and list of arguments

[Tab]           Completes the command/word. If the input is ambiguous,
                a second [Tab] gives possible options

/               Move up to base level
..              Move up one level
/command        Use command at the base level
ReichNet - Authorized administrators only. Access to this device is monitored.
[38636@ReichHub] > export hide-sensitive
# aug/08/2019 16:02:57 by RouterOS 6.44.5
# software id = 1SBQ-KUIK
#
# model = RouterBOARD 3011UiAS
# serial number = 8EEE0A24B654
/interface l2tp-server
add name=reichnet-3978 user=3978
add name=reichnet-8794 user=8794
/interface bridge
add admin-mac=74:4D:28:2F:4E:2D auto-mac=no name=bridge protocol-mode=none
add name=guestbridge protocol-mode=none
/interface ethernet
set [ find default-name=ether2 ] name=OutToHouse speed=100Mbps
set [ find default-name=ether1 ] name=OutToWAN speed=100Mbps
set [ find default-name=ether3 ] name=ReichNet-GUEST speed=100Mbps
set [ find default-name=sfp1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full auto-negotiation=no name=SFP-RackSwitch speed=10Gbps
set [ find default-name=ether4 ] disabled=yes speed=100Mbps
set [ find default-name=ether5 ] disabled=yes speed=100Mbps
set [ find default-name=ether6 ] disabled=yes speed=100Mbps
set [ find default-name=ether7 ] disabled=yes speed=100Mbps
set [ find default-name=ether8 ] disabled=yes speed=100Mbps
set [ find default-name=ether9 ] disabled=yes speed=100Mbps
set [ find default-name=ether10 ] disabled=yes speed=100Mbps
/interface vlan
add interface=bridge mtu=1504 name=srv-vlan vlan-id=50
add arp=proxy-arp interface=bridge mtu=1504 name=vpn-vlan vlan-id=60
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
add name=PPP
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=ReichNet
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip ipsec peer
add name=peer1 passive=yes
/ip ipsec profile
set [ find default=yes ] dh-group=modp2048 dpd-maximum-failures=2 enc-algorithm=aes-256,aes-128,3des
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-256-cbc,aes-192-cbc,aes-128-cbc,3des pfs-group=none
/ip pool
add name=dhcp ranges=10.0.0.101-10.0.0.254
add name=VPN-L2TP ranges=172.16.0.10-172.16.0.254
add name=dhcp-guest ranges=20.0.0.10-20.0.0.75
add name=dhcp-server ranges=30.0.0.10-30.0.0.75
add name=dhcp-vpn ranges=172.32.0.10-172.32.0.50
add name=dhcp-vpn-remote ranges=172.32.0.51-172.32.0.100
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge name=rst
add address-pool=dhcp-guest disabled=no interface=guestbridge name=guest
add address-pool=dhcp-server disabled=no interface=srv-vlan name=srv
add address-pool=dhcp-vpn disabled=no interface=vpn-vlan name=vpn
/ppp profile
add change-tcp-mss=yes local-address=172.32.0.1 name=VPN-L2TP remote-address=dhcp-vpn-remote use-encryption=yes
/queue interface
set OutToWAN queue=ethernet-default
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/interface bridge port
add bridge=bridge comment=defconf interface=OutToHouse
add bridge=guestbridge comment=defconf interface=ReichNet-GUEST
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=ether9
add bridge=bridge comment=defconf interface=ether10
add bridge=bridge comment=defconf interface=SFP-RackSwitch
/ip neighbor discovery-settings
set discover-interface-list=none
/interface bridge vlan
add bridge=bridge vlan-ids=50
add bridge=bridge vlan-ids=60
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set authentication=mschap2 default-profile=VPN-L2TP enabled=yes keepalive-timeout=disabled max-mtu=1500
/interface list member
add interface=bridge list=LAN
add comment=defconf interface=OutToWAN list=WAN
add interface=guestbridge list=LAN
/interface ovpn-server server
set certificate=reichnetwork_net.ca-bundle_2 cipher=blowfish128,aes128,aes192,aes256
/interface pptp-server server
set default-profile=default
/interface sstp-server server
set authentication=mschap1,mschap2 certificate=reichnetwork_net.crt_0
/ip address
add address=10.0.0.1/24 comment=defconf interface=OutToHouse network=10.0.0.0
add address=**REMOVED**/24 interface=OutToWAN network=**REMOVED**
add address=20.0.0.1/24 interface=guestbridge network=20.0.0.0
add address=30.0.0.1/24 interface=srv-vlan network=30.0.0.0
add address=172.32.0.1/24 interface=vpn-vlan network=172.32.0.0
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid interface=OutToWAN
/ip dhcp-server lease
add address=10.0.0.16 client-id=1:ec:71:db:f2:d8:7c comment=CAMBACKYARD-N mac-address=EC:71:DB:F2:D8:7C server=rst
add address=10.0.0.14 client-id=1:ec:71:db:15:5e:4 comment=CAMBACKYARD-S mac-address=EC:71:DB:15:5E:04 server=rst
add address=10.0.0.15 client-id=1:ec:71:db:c7:73:6a comment=CAMFRONTYARD-E mac-address=EC:71:DB:C7:73:6A server=rst
add address=10.0.0.3 comment=P000EPRIMARY mac-address=00:0E:B6:30:89:88 server=rst
add address=10.0.0.2 comment=P000EPRIMARY mac-address=00:0E:B6:30:89:89 server=rst
add address=10.0.0.74 client-id=1:a4:2b:b0:20:74:df comment=WIRELESS-ADAPTER-PRIVATE mac-address=A4:2B:B0:20:74:DF server=rst
add address=10.0.0.28 always-broadcast=yes client-id=1:d8:cb:8a:5f:15:cb comment=PD8CBCAMERA mac-address=D8:CB:8A:5F:15:CB server=rst
add address=10.0.0.11 client-id=1:0:15:5d:0:6:0 comment=V782BDOWNLOAD mac-address=00:15:5D:00:06:00 server=rst
add address=10.0.0.30 comment=V782BDROPBOX mac-address=00:15:5D:00:06:04 server=rst
add address=10.0.0.46 client-id=1:0:26:b9:62:27:e4 comment=P0026VIRTUAL mac-address=00:26:B9:62:27:E4 server=rst
add address=10.0.0.47 client-id=1:0:26:b9:62:27:e0 comment=P0026VIRTUAL mac-address=00:26:B9:62:27:E0 server=rst
add address=10.0.0.48 client-id=1:0:26:b9:62:27:de comment=P0026VIRTUAL mac-address=00:26:B9:62:27:DE server=rst
add address=10.0.0.51 client-id=1:34:97:f6:b7:2:43 comment=JORDAN-DESKTOP mac-address=34:97:F6:B7:02:43 server=rst
add address=10.0.0.39 client-id=1:0:15:5d:0:2e:4 comment=V0026WEBHUB mac-address=00:15:5D:00:2E:04 server=rst
add address=10.0.0.4 comment=V0026PXEBOOT mac-address=00:15:5D:00:2E:0A server=rst
add address=10.0.0.49 client-id=1:98:5f:d3:5b:e5:6c comment=JORDAN-WORKPC mac-address=98:5F:D3:5B:E5:6C server=rst
add address=10.0.0.37 comment=V0026IRC mac-address=00:15:5D:00:2E:13 server=rst
add address=10.0.0.52 client-id=1:d8:c4:97:a0:44:84 comment=CARLY-LAPTOP mac-address=D8:C4:97:A0:44:84 server=rst
add address=10.0.0.36 client-id=1:0:15:5d:0:2e:1b comment=V0026JCWIN2016 mac-address=00:15:5D:00:2E:1B server=rst
add address=10.0.0.50 client-id=1:1c:1b:d:ec:a7:b3 comment=CDELABARRE-PC mac-address=1C:1B:0D:EC:A7:B3 server=rst
add address=10.0.0.53 client-id=1:0:15:5d:0:2e:25 comment=V0026WORKVPN mac-address=00:15:5D:00:2E:25 server=rst
add address=10.0.0.101 client-id=1:0:4:4b:48:9b:27 comment=SHIELD-GSTNET mac-address=00:04:4B:48:9B:27 server=rst
add address=10.0.0.103 comment=TV-LVRM-GSTNET mac-address=C4:1C:FF:5B:6D:5B server=rst
add address=10.0.0.100 client-id=1:74:4d:28:18:a2:94 comment="SFP SWITCH CONN" mac-address=74:4D:28:18:A2:94 server=rst
add address=20.0.0.5 client-id=1:14:91:82:c7:7e:16 comment=REICHNET-GUEST mac-address=14:91:82:C7:7E:16 server=guest
add address=10.0.0.5 comment=V0026RADIUS mac-address=00:15:5D:00:2E:2C server=rst
add address=30.0.0.25 client-id=ff:5d:0:28:4:0:1:0:1:24:b7:72:a7:0:15:5d:0:28:4 comment="V0019DEREK - NEXTCLOUD" mac-address=00:15:5D:00:28:04 server=srv
add address=30.0.0.40 client-id=1:0:19:b9:d8:38:31 comment=P0019DEREK mac-address=00:19:B9:D8:38:31 server=srv
add address=30.0.0.50 client-id=1:0:15:5d:0:6:3 comment=V0026MEDIA mac-address=00:15:5D:00:06:03 server=srv
add address=30.0.0.20 client-id=ff:c4:af:ec:9c:0:2:0:0:ab:11:11:f8:3c:4e:47:e8:6:9b comment=V0026LIBCATALOG mac-address=00:15:5D:00:2E:27 server=srv
add address=30.0.0.11 client-id=ff:80:40:df:4e:0:2:0:0:ab:11:c:b8:8a:f8:1d:7e:9a:19 comment=V0026JITSI mac-address=00:15:5D:00:2E:28 server=srv
add address=30.0.0.15 client-id=ff:72:c3:8f:6c:0:2:0:0:ab:11:f2:9e:5d:5f:4d:23:b5:78 comment=V0026CARLYMAILTRAIN mac-address=00:15:5D:00:2E:02 server=srv
add address=30.0.0.5 client-id=1:0:26:b9:62:27:e0 comment="P0026VIRTUAL - SERVER" mac-address=00:26:B9:62:27:E0 server=srv
add address=30.0.0.30 client-id=1:0:15:5d:0:2e:12 comment=V0026EXCHANGE mac-address=00:15:5D:00:2E:12 server=srv
add address=10.0.0.10 client-id=1:0:15:5d:0:2e:2e comment=V0026MDM mac-address=00:15:5D:00:2E:2E server=rst
add address=10.0.0.20 client-id=ff:2:8c:1:76:0:2:0:0:ab:11:97:23:58:ed:da:78:48:f3 comment=V0026HOMEASSIST mac-address=00:15:5D:00:2E:31 server=rst
add address=172.32.0.25 client-id=1:0:29:fa:aa:aa:81 comment=V0026RDG mac-address=00:29:FA:AA:AA:81 server=vpn
add address=172.32.0.9 client-id=1:78:2b:cb:9:26:2a comment=STORAGE-VPN mac-address=78:2B:CB:09:26:2A server=vpn
add address=172.32.0.45 client-id=1:0:26:b9:62:27:e2 comment=P0026VIRTUAL-VPN mac-address=00:26:B9:62:27:E2 server=vpn
/ip dhcp-server network
add address=10.0.0.0/24 gateway=10.0.0.1 netmask=24
add address=20.0.0.0/24 gateway=20.0.0.1 netmask=24
add address=30.0.0.0/24 gateway=30.0.0.1 netmask=24
add address=172.32.0.0/24 gateway=172.32.0.1
/ip dns
set allow-remote-requests=yes servers=10.0.0.3
/ip dns static
add address=10.0.0.1 name=router.lan
add address=10.0.0.1 name=router
/ip firewall address-list
add address=216.92.61.7 list=blacklist
add address=10.0.0.101 list=hardwire-block
add address=10.0.0.103 list=hardwire-block
add address=69.20.59.81 list=blacklist
add address=69.20.59.80 list=blacklist
add address=20.0.0.0/24 list=38636-30/24-DENY
add address=10.0.0.0/24 list=38636-30/24-DENY
add address=plex.tv list=38636-30/24-PERMIT
add address=30.0.0.50 list=38636-30/24-PLEX
add address=30.0.0.40 list=38636-30/24-PLEX
add address=10.0.0.0/24 list=38636-172.32/24-DENY
add address=20.0.0.0/24 list=38636-172.32/24-DENY
add address=30.0.0.0/24 list=38636-172.32/24-DENY
/ip firewall filter
add action=fasttrack-connection chain=forward comment="38636-ALL: defconf fasttrack" connection-state=established,related
add action=accept chain=forward comment="38636-172.32/24: allow RDG access to LAN" dst-address-list="" out-interface=bridge src-address=172.32.0.25
add action=accept chain=forward comment="38636-172.32/24: allow RDG access to WAN" dst-address-list="" out-interface=OutToWAN src-address=172.32.0.25
add action=drop chain=forward comment="38636-172.32/24: deny to SERVER,GUEST,INTERNAL" dst-address-list=38636-40/24-DENY out-interface=bridge src-address=172.32.0.0/24
add action=drop chain=forward comment="38636-172.32/24: deny all to WAN" out-interface=OutToWAN src-address=172.32.0.0/24
add action=accept chain=input comment="38636-ALL: defconf accept established,related" connection-state=established,related
add action=accept chain=forward comment="38636-ALL: defconf accept established,related" connection-state=established,related
add action=accept chain=input comment="38636-ALL: Winbox" dst-port=8291 protocol=tcp
add action=accept chain=forward comment="38636-ALL: NAT Traffic Permit" dst-port=443,4430,1000,32400,8096,26555,81,80,8081,3000,9383 in-interface=OutToWAN protocol=tcp
add action=accept chain=input comment="38636-ALL: L2TP 1701" dst-port=1701 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP 500" dst-port=500 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP 4500" dst-port=4500 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP PRTL 50" protocol=ipsec-esp
add action=accept chain=forward comment="38636-30/24: TCP allow for AD" dst-address=10.0.0.3 dst-port=53,88,135,139,389,445,464,636,3268,3269,5722,9389 out-interface=bridge protocol=tcp src-address=\
    30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: UDP allow for AD" dst-address=10.0.0.3 dst-port=53,67,88,123,137,138,389,123,445,2535 out-interface=bridge port="" protocol=udp src-address=\
    30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Storage access 10.0.0.9 TCP" dst-address=10.0.0.9 dst-port=135-139,445 out-interface=bridge protocol=tcp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Storage access 10.0.0.9 UDP" dst-address=10.0.0.9 dst-port=135-139,445 out-interface=bridge protocol=udp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: accept machine PINGS into INTERNAL" dst-address=10.0.0.0/24 out-interface=bridge protocol=icmp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Allow dynamic port ranges" dst-address=10.0.0.0/24 dst-port="" out-interface=bridge protocol=tcp src-address=30.0.0.0/24 src-port=49152-65535
add action=accept chain=forward comment="38636-30/24: PLEX external permit" dst-address-list=38636-30/24-PERMIT out-interface=OutToWAN src-address-list=38636-30/24-PLEX
add action=accept chain=forward comment="Remote-Site: RouterOS netflow to ELK-Stack" dst-address=10.0.0.33 dst-port=2055 in-interface=all-ppp protocol=udp
add action=accept chain=forward comment="Remote-Site: Allow dynamic port ranges" dst-port="" in-interface=all-ppp protocol=tcp src-port=49152-65535
add action=accept chain=forward comment="Remote-Site: Allow PXE server access" dst-port="" in-interface=all-ppp protocol=udp src-port=4011
add action=accept chain=forward comment="Remote-Site: TCP allow for AD" dst-address=10.0.0.3 dst-port=53,88,135,139,389,445,464,636,3268,3269,5722,9389 in-interface=all-ppp protocol=tcp
add action=accept chain=forward comment="Remote-Site: UDP allow for AD" dst-address=10.0.0.3 dst-port=53,67,88,123,137,138,389,123,445,2535 in-interface=all-ppp port="" protocol=udp
add action=accept chain=forward comment="Remote-Site: Storage access 10.0.0.9 TCP" dst-address=10.0.0.9 dst-port=135-139,445 in-interface=all-ppp protocol=tcp
add action=accept chain=forward comment="Remote-Site: Storage access 10.0.0.9 UDP" dst-address=10.0.0.9 dst-port=135-139,445 in-interface=all-ppp protocol=udp
add action=drop chain=forward comment="38636-ALL: TCP Address Blacklist" dst-address-list=blacklist protocol=tcp
add action=drop chain=forward comment="38636-ALL: defconf drop invalid" connection-state=invalid
add action=drop chain=forward comment="38636-ALL: defconf drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=OutToWAN
add action=drop chain=input comment="38636-ALL: drop all INPUT (WAN)" in-interface=OutToWAN log=yes log-prefix=Drop_Input_WAN
add action=drop chain=forward comment="38636-ALL: drop all FORWARD (WAN)" in-interface=OutToWAN log=yes log-prefix=Drop_Forward_WAN
add action=drop chain=forward comment="38636-30/24: deny all to WAN" out-interface=OutToWAN src-address=30.0.0.0/24
add action=drop chain=forward comment="38636-30/24: deny all to GUEST/INTERNAL" dst-address-list=38636-30/24 out-interface=bridge src-address=30.0.0.0/24
add action=drop chain=forward comment="38636-20/24: drop all GST hardwire traffic to RST" dst-address=10.0.0.0/24 out-interface=bridge src-address-list=hardwire-block
add action=drop chain=forward comment="PPP: drop all FORWARD from VPN" in-interface=all-ppp log-prefix=VPNdrop
add action=drop chain=input comment="PPP: drop all INPUT from VPN" in-interface=all-ppp log-prefix=VPNdrop
add action=drop chain=forward comment="GUEST: Deny all to primary network" dst-address=10.0.0.0/24 in-interface=guestbridge src-address=20.0.0.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=OutToWAN
add action=dst-nat chain=dstnat comment="HTTPS PASSWORD 1000" dst-port=1000 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.2 to-ports=1000
add action=dst-nat chain=dstnat comment="PLEX PORT 32400 TCP" dst-port=32400 in-interface=OutToWAN protocol=tcp to-addresses=30.0.0.50 to-ports=32400
add action=dst-nat chain=dstnat comment="EMBY PORT 8096 TCP" dst-port=8096 in-interface=OutToWAN protocol=tcp to-addresses=30.0.0.50 to-ports=8096
add action=dst-nat chain=dstnat comment="MDM PORT 9383" dst-port=9383 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.10 to-ports=9383
add action=dst-nat chain=dstnat comment=P0019DEREK-PLEX dst-port=26555 in-interface=OutToWAN protocol=tcp to-addresses=30.0.0.40 to-ports=32400
add action=dst-nat chain=dstnat comment="HTTP WEBHUB TRAFFIC 80" dst-port=80 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.39 to-ports=80
add action=dst-nat chain=dstnat comment="HTTPS WEBHUB TRAFFIC 443" dst-port=443 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.2 to-ports=443
add action=dst-nat chain=dstnat comment="HTTPS PASSWORD 1000" dst-port=1000 in-interface=all-ethernet protocol=tcp to-addresses=10.0.0.2 to-ports=1000
add action=dst-nat chain=dstnat comment="SECURITY CAMERA SYSTEM 8081" dst-port=8081 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.28 to-ports=8081
add action=dst-nat chain=dstnat comment="HTTPS MAILTRAIN 3000" dst-port=3000 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.34 to-ports=3000
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47984 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=47984
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47989 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=47989
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48010 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=48010
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47998 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=47998
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47999 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=47999
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48000 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48000
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48002 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48002
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48010 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48010
/ip firewall service-port
set ftp ports=212
/ip ipsec identity
add generate-policy=port-override peer=peer1 remote-id=ignore
/ip route
add distance=1 gateway=**REMOVED**
add distance=1 dst-address=10.0.1.0/24 gateway=reichnet-8794
add distance=1 dst-address=10.0.2.0/24 gateway=reichnet-3978
add distance=1 dst-address=172.16.0.0/24 gateway=bridge
/ip service
set telnet disabled=yes
set ftp disabled=yes port=212
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip traffic-flow
set cache-entries=128k enabled=yes
/ip traffic-flow target
add dst-address=10.0.0.33
/ip upnp
set enabled=yes
/ppp aaa
set use-radius=yes
/ppp secret
add local-address=172.16.0.1 name=8794 profile=VPN-L2TP remote-address=172.16.0.240 service=l2tp
add local-address=172.16.0.1 name=3978 profile=VPN-L2TP remote-address=172.16.0.242 service=l2tp
add local-address=172.32.0.1 name=admin_bypass remote-address=172.32.0.100 service=l2tp
/radius
add address=10.0.0.5 realm=reichnetwork service=ppp,login,ipsec src-address=10.0.0.1
/snmp
set enabled=yes
/system clock
set time-zone-name=America/Los_Angeles
/system identity
set name=ReichHub
/system logging
add disabled=yes topics=ipsec
add topics=sstp
/system note
set note="ReichNet - Authorized administrators only. Access to this device is monitored."
/system package update
set channel=long-term
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/user aaa
set use-radius=yes
[38636@ReichHub] >

Any thoughts you may have would be appreciated!

Try to watch the resources like Cpu usage!!! In profile you can see with resource is used to cpu. it’s a good start to investigate.

From first sight I’d say that it’s bridge-related.
You have two bridges on the same physical switch chip (which covers sfp and ether1-5).
And hw-offload is only available for one bridge per switch chip. So I guess that your link-local traffic is going through the CPU.

It looks that you don’t really need a brigde for your guest network at all. Try moving your guest network to switch chip 2 (ether6…10) and put IP and dhcp server directly on the ethernet interface.
And before doing that, remove ether6…10 from the existing bridge - they’re disabled anyway.

Good luck,
-Chris

Totally agree. But even with everything going on the max usage that I’ve been able to record has been about 17%. So I don’t think that’s directly the problem.

@Chris - Thanks for the suggestions with changing around the bridge. I’ll work on making those changes in the morning and report back on the results.

These changes appear to have been a step in the right direction! I am now holding in the ~40 MB/s range. Which is much better than the 12 I was getting but still short of normal.
transfer-rate.png
NEVERMIND I lied. We were doing good and now I had a drop back down to 3.81 MB/s and it has paused itself again.
transfer-rate-drop.png
Updated settings file:

 MMM      MMM       KKK                          TTTTTTTTTTT      KKK
  MMMM    MMMM       KKK                          TTTTTTTTTTT      KKK
  MMM MMMM MMM  III  KKK  KKK  RRRRRR     OOOOOO      TTT     III  KKK  KKK
  MMM  MM  MMM  III  KKKKK     RRR  RRR  OOO  OOO     TTT     III  KKKKK
  MMM      MMM  III  KKK KKK   RRRRRR    OOO  OOO     TTT     III  KKK KKK
  MMM      MMM  III  KKK  KKK  RRR  RRR   OOOOOO      TTT     III  KKK  KKK

  MikroTik RouterOS 6.44.5 (c) 1999-2019       http://www.mikrotik.com/

[?]             Gives the list of available commands
command [?]     Gives help on the command and list of arguments

[Tab]           Completes the command/word. If the input is ambiguous,
                a second [Tab] gives possible options

/               Move up to base level
..              Move up one level
/command        Use command at the base level
ReichNet - Authorized administrators only. Access to this device is monitored.
[38636@ReichHub] > export hide-sensitive
# aug/09/2019 07:23:22 by RouterOS 6.44.5
# software id = 1SBQ-KUIK
#
# model = RouterBOARD 3011UiAS
# serial number = 8EEE0A24B654
/interface l2tp-server
add name=reichnet-3978 user=3978
add name=reichnet-8794 user=8794
/interface bridge
add admin-mac=74:4D:28:2F:4E:2D auto-mac=no name=bridge protocol-mode=none
/interface ethernet
set [ find default-name=ether2 ] name=OutToHouse speed=100Mbps
set [ find default-name=ether1 ] name=OutToWAN speed=100Mbps
set [ find default-name=ether6 ] name=ReichNet-GUEST speed=100Mbps
set [ find default-name=sfp1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full auto-negotiation=no name=SFP-RackSwitch speed=10Gbps
set [ find default-name=ether3 ] disabled=yes speed=100Mbps
set [ find default-name=ether4 ] disabled=yes speed=100Mbps
set [ find default-name=ether5 ] disabled=yes speed=100Mbps
set [ find default-name=ether7 ] disabled=yes speed=100Mbps
set [ find default-name=ether8 ] disabled=yes speed=100Mbps
set [ find default-name=ether9 ] disabled=yes speed=100Mbps
set [ find default-name=ether10 ] disabled=yes speed=100Mbps
/interface vlan
add interface=bridge mtu=1504 name=srv-vlan vlan-id=50
add arp=proxy-arp interface=bridge mtu=1504 name=vpn-vlan vlan-id=60
/interface ethernet switch port
set 5 default-vlan-id=0 vlan-mode=fallback
set 6 default-vlan-id=0 vlan-mode=fallback
set 7 default-vlan-id=0 vlan-mode=fallback
set 8 default-vlan-id=0 vlan-mode=fallback
set 9 default-vlan-id=0 vlan-mode=fallback
set 11 default-vlan-id=0 vlan-mode=fallback
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
add name=PPP
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=ReichNet
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip ipsec peer
add name=peer1 passive=yes
/ip ipsec profile
set [ find default=yes ] dh-group=modp2048 dpd-maximum-failures=2 enc-algorithm=aes-256,aes-128,3des
/ip ipsec proposal
set [ find default=yes ] enc-algorithms=aes-256-cbc,aes-192-cbc,aes-128-cbc,3des pfs-group=none
/ip pool
add name=dhcp ranges=10.0.0.101-10.0.0.254
add name=VPN-L2TP ranges=172.16.0.10-172.16.0.254
add name=dhcp-guest ranges=20.0.0.10-20.0.0.75
add name=dhcp-server ranges=30.0.0.10-30.0.0.75
add name=dhcp-vpn ranges=172.32.0.10-172.32.0.50
add name=dhcp-vpn-remote ranges=172.32.0.51-172.32.0.100
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge name=rst
add address-pool=dhcp-guest disabled=no interface=ReichNet-GUEST name=guest
add address-pool=dhcp-server disabled=no interface=srv-vlan name=srv
add address-pool=dhcp-vpn disabled=no interface=vpn-vlan name=vpn
/ppp profile
add change-tcp-mss=yes local-address=172.32.0.1 name=VPN-L2TP remote-address=dhcp-vpn-remote use-encryption=yes
/queue interface
set OutToWAN queue=ethernet-default
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/interface bridge port
add bridge=bridge comment=defconf interface=OutToHouse
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=SFP-RackSwitch
add bridge=bridge interface=ether3
/ip neighbor discovery-settings
set discover-interface-list=none
/interface bridge vlan
add bridge=bridge vlan-ids=50
add bridge=bridge vlan-ids=60
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set authentication=mschap2 default-profile=VPN-L2TP enabled=yes keepalive-timeout=disabled max-mtu=1500
/interface list member
add interface=bridge list=LAN
add comment=defconf interface=OutToWAN list=WAN
add list=LAN
/interface ovpn-server server
set certificate=reichnetwork_net.ca-bundle_2 cipher=blowfish128,aes128,aes192,aes256
/interface pptp-server server
set default-profile=default
/interface sstp-server server
set authentication=mschap1,mschap2 certificate=reichnetwork_net.crt_0
/ip address
add address=10.0.0.1/24 comment=defconf interface=OutToHouse network=10.0.0.0
add address=**REMOVED**/24 interface=OutToWAN network=**REMOVED**
add address=20.0.0.1/24 interface=ReichNet-GUEST network=20.0.0.0
add address=30.0.0.1/24 interface=srv-vlan network=30.0.0.0
add address=172.32.0.1/24 interface=vpn-vlan network=172.32.0.0
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid interface=OutToWAN
/ip dhcp-server lease
add address=10.0.0.16 client-id=1:ec:71:db:f2:d8:7c comment=CAMBACKYARD-N mac-address=EC:71:DB:F2:D8:7C server=rst
add address=10.0.0.14 client-id=1:ec:71:db:15:5e:4 comment=CAMBACKYARD-S mac-address=EC:71:DB:15:5E:04 server=rst
add address=10.0.0.15 client-id=1:ec:71:db:c7:73:6a comment=CAMFRONTYARD-E mac-address=EC:71:DB:C7:73:6A server=rst
add address=10.0.0.3 comment=P000EPRIMARY mac-address=00:0E:B6:30:89:88 server=rst
add address=10.0.0.2 comment=P000EPRIMARY mac-address=00:0E:B6:30:89:89 server=rst
add address=10.0.0.74 client-id=1:a4:2b:b0:20:74:df comment=WIRELESS-ADAPTER-PRIVATE mac-address=A4:2B:B0:20:74:DF server=rst
add address=10.0.0.28 always-broadcast=yes client-id=1:d8:cb:8a:5f:15:cb comment=PD8CBCAMERA mac-address=D8:CB:8A:5F:15:CB server=rst
add address=10.0.0.11 client-id=1:0:15:5d:0:6:0 comment=V782BDOWNLOAD mac-address=00:15:5D:00:06:00 server=rst
add address=10.0.0.30 comment=V782BDROPBOX mac-address=00:15:5D:00:06:04 server=rst
add address=10.0.0.46 client-id=1:0:26:b9:62:27:e4 comment=P0026VIRTUAL mac-address=00:26:B9:62:27:E4 server=rst
add address=10.0.0.47 client-id=1:0:26:b9:62:27:e0 comment=P0026VIRTUAL mac-address=00:26:B9:62:27:E0 server=rst
add address=10.0.0.48 client-id=1:0:26:b9:62:27:de comment=P0026VIRTUAL mac-address=00:26:B9:62:27:DE server=rst
add address=10.0.0.51 client-id=1:34:97:f6:b7:2:43 comment=JORDAN-DESKTOP mac-address=34:97:F6:B7:02:43 server=rst
add address=10.0.0.39 client-id=1:0:15:5d:0:2e:4 comment=V0026WEBHUB mac-address=00:15:5D:00:2E:04 server=rst
add address=10.0.0.4 comment=V0026PXEBOOT mac-address=00:15:5D:00:2E:0A server=rst
add address=10.0.0.49 client-id=1:98:5f:d3:5b:e5:6c comment=JORDAN-WORKPC mac-address=98:5F:D3:5B:E5:6C server=rst
add address=10.0.0.37 comment=V0026IRC mac-address=00:15:5D:00:2E:13 server=rst
add address=10.0.0.52 client-id=1:d8:c4:97:a0:44:84 comment=CARLY-LAPTOP mac-address=D8:C4:97:A0:44:84 server=rst
add address=10.0.0.36 client-id=1:0:15:5d:0:2e:1b comment=V0026JCWIN2016 mac-address=00:15:5D:00:2E:1B server=rst
add address=10.0.0.50 client-id=1:1c:1b:d:ec:a7:b3 comment=CDELABARRE-PC mac-address=1C:1B:0D:EC:A7:B3 server=rst
add address=10.0.0.53 client-id=1:0:15:5d:0:2e:25 comment=V0026WORKVPN mac-address=00:15:5D:00:2E:25 server=rst
add address=10.0.0.101 client-id=1:0:4:4b:48:9b:27 comment=SHIELD-GSTNET mac-address=00:04:4B:48:9B:27 server=rst
add address=10.0.0.103 comment=TV-LVRM-GSTNET mac-address=C4:1C:FF:5B:6D:5B server=rst
add address=10.0.0.100 client-id=1:74:4d:28:18:a2:94 comment="SFP SWITCH CONN" mac-address=74:4D:28:18:A2:94 server=rst
add address=20.0.0.5 client-id=1:14:91:82:c7:7e:16 comment=REICHNET-GUEST mac-address=14:91:82:C7:7E:16 server=guest
add address=10.0.0.5 comment=V0026RADIUS mac-address=00:15:5D:00:2E:2C server=rst
add address=30.0.0.25 client-id=ff:5d:0:28:4:0:1:0:1:24:b7:72:a7:0:15:5d:0:28:4 comment="V0019DEREK - NEXTCLOUD" mac-address=00:15:5D:00:28:04 server=srv
add address=30.0.0.40 client-id=1:0:19:b9:d8:38:31 comment=P0019DEREK mac-address=00:19:B9:D8:38:31 server=srv
add address=30.0.0.20 client-id=ff:c4:af:ec:9c:0:2:0:0:ab:11:11:f8:3c:4e:47:e8:6:9b comment=V0026LIBCATALOG mac-address=00:15:5D:00:2E:27 server=srv
add address=30.0.0.11 client-id=ff:80:40:df:4e:0:2:0:0:ab:11:c:b8:8a:f8:1d:7e:9a:19 comment=V0026JITSI mac-address=00:15:5D:00:2E:28 server=srv
add address=30.0.0.15 client-id=ff:72:c3:8f:6c:0:2:0:0:ab:11:f2:9e:5d:5f:4d:23:b5:78 comment=V0026CARLYMAILTRAIN mac-address=00:15:5D:00:2E:02 server=srv
add address=30.0.0.5 client-id=1:0:26:b9:62:27:e0 comment="P0026VIRTUAL - SERVER" mac-address=00:26:B9:62:27:E0 server=srv
add address=30.0.0.30 client-id=1:0:15:5d:0:2e:12 comment=V0026EXCHANGE mac-address=00:15:5D:00:2E:12 server=srv
add address=10.0.0.10 client-id=1:0:15:5d:0:2e:2e comment=V0026MDM mac-address=00:15:5D:00:2E:2E server=rst
add address=10.0.0.20 client-id=ff:2:8c:1:76:0:2:0:0:ab:11:97:23:58:ed:da:78:48:f3 comment=V0026HOMEASSIST mac-address=00:15:5D:00:2E:31 server=rst
add address=172.32.0.25 client-id=1:0:29:fa:aa:aa:81 comment=V0026RDG mac-address=00:29:FA:AA:AA:81 server=vpn
add address=172.32.0.9 client-id=1:78:2b:cb:9:26:2a comment=STORAGE-VPN mac-address=78:2B:CB:09:26:2A server=vpn
add address=172.32.0.45 client-id=1:0:26:b9:62:27:e2 comment=P0026VIRTUAL-VPN mac-address=00:26:B9:62:27:E2 server=vpn
add address=10.0.0.27 client-id=1:0:15:5d:0:6:3 mac-address=00:15:5D:00:06:03 server=rst
/ip dhcp-server network
add address=10.0.0.0/24 gateway=10.0.0.1 netmask=24
add address=20.0.0.0/24 gateway=20.0.0.1 netmask=24
add address=30.0.0.0/24 gateway=30.0.0.1 netmask=24
add address=172.32.0.0/24 gateway=172.32.0.1
/ip dns
set allow-remote-requests=yes servers=10.0.0.3
/ip dns static
add address=10.0.0.1 name=router.lan
add address=10.0.0.1 name=router
/ip firewall address-list
add address=216.92.61.7 list=blacklist
add address=10.0.0.101 list=hardwire-block
add address=10.0.0.103 list=hardwire-block
add address=69.20.59.81 list=blacklist
add address=69.20.59.80 list=blacklist
add address=20.0.0.0/24 list=38636-30/24-DENY
add address=10.0.0.0/24 list=38636-30/24-DENY
add address=plex.tv list=38636-30/24-PERMIT
add address=30.0.0.50 list=38636-30/24-PLEX
add address=30.0.0.40 list=38636-30/24-PLEX
add address=10.0.0.0/24 list=38636-172.32/24-DENY
add address=20.0.0.0/24 list=38636-172.32/24-DENY
add address=30.0.0.0/24 list=38636-172.32/24-DENY
/ip firewall filter
add action=fasttrack-connection chain=forward comment="38636-ALL: defconf fasttrack" connection-state=established,related
add action=accept chain=forward comment="38636-172.32/24: allow RDG access to LAN" dst-address-list="" out-interface=bridge src-address=172.32.0.25
add action=accept chain=forward comment="38636-172.32/24: allow RDG access to WAN" dst-address-list="" out-interface=OutToWAN src-address=172.32.0.25
add action=drop chain=forward comment="38636-172.32/24: deny to SERVER,GUEST,INTERNAL" dst-address-list=38636-40/24-DENY out-interface=bridge src-address=172.32.0.0/24
add action=drop chain=forward comment="38636-172.32/24: deny all to WAN" out-interface=OutToWAN src-address=172.32.0.0/24
add action=accept chain=input comment="38636-ALL: defconf accept established,related" connection-state=established,related
add action=accept chain=forward comment="38636-ALL: defconf accept established,related" connection-state=established,related
add action=accept chain=input comment="38636-ALL: Winbox" dst-port=8291 protocol=tcp
add action=accept chain=forward comment="38636-ALL: NAT Traffic Permit" dst-port=443,4430,1000,32400,8096,26555,81,80,8081,3000,9383 in-interface=OutToWAN protocol=tcp
add action=accept chain=input comment="38636-ALL: L2TP 1701" dst-port=1701 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP 500" dst-port=500 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP 4500" dst-port=4500 protocol=udp
add action=accept chain=input comment="38636-ALL: L2TP PRTL 50" protocol=ipsec-esp
add action=accept chain=forward comment="38636-30/24: TCP allow for AD" dst-address=10.0.0.3 dst-port=53,88,135,139,389,445,464,636,3268,3269,5722,9389 out-interface=bridge protocol=tcp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: UDP allow for AD" dst-address=10.0.0.3 dst-port=53,67,88,123,137,138,389,123,445,2535 out-interface=bridge port="" protocol=udp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Storage access 10.0.0.9 TCP" dst-address=10.0.0.9 dst-port=135-139,445 out-interface=bridge protocol=tcp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Storage access 10.0.0.9 UDP" dst-address=10.0.0.9 dst-port=135-139,445 out-interface=bridge protocol=udp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: accept machine PINGS into INTERNAL" dst-address=10.0.0.0/24 out-interface=bridge protocol=icmp src-address=30.0.0.0/24
add action=accept chain=forward comment="38636-30/24: Allow dynamic port ranges" dst-address=10.0.0.0/24 dst-port="" out-interface=bridge protocol=tcp src-address=30.0.0.0/24 src-port=49152-65535
add action=accept chain=forward comment="38636-30/24: PLEX external permit" dst-address-list=38636-30/24-PERMIT out-interface=OutToWAN src-address-list=38636-30/24-PLEX
add action=accept chain=forward comment="Remote-Site: RouterOS netflow to ELK-Stack" dst-address=10.0.0.33 dst-port=2055 in-interface=all-ppp protocol=udp
add action=accept chain=forward comment="Remote-Site: Allow dynamic port ranges" dst-port="" in-interface=all-ppp protocol=tcp src-port=49152-65535
add action=accept chain=forward comment="Remote-Site: Allow PXE server access" dst-port="" in-interface=all-ppp protocol=udp src-port=4011
add action=accept chain=forward comment="Remote-Site: TCP allow for AD" dst-address=10.0.0.3 dst-port=53,88,135,139,389,445,464,636,3268,3269,5722,9389 in-interface=all-ppp protocol=tcp
add action=accept chain=forward comment="Remote-Site: UDP allow for AD" dst-address=10.0.0.3 dst-port=53,67,88,123,137,138,389,123,445,2535 in-interface=all-ppp port="" protocol=udp
add action=accept chain=forward comment="Remote-Site: Storage access 10.0.0.9 TCP" dst-address=10.0.0.9 dst-port=135-139,445 in-interface=all-ppp protocol=tcp
add action=accept chain=forward comment="Remote-Site: Storage access 10.0.0.9 UDP" dst-address=10.0.0.9 dst-port=135-139,445 in-interface=all-ppp protocol=udp
add action=drop chain=forward comment="38636-ALL: TCP Address Blacklist" dst-address-list=blacklist protocol=tcp
add action=drop chain=forward comment="38636-ALL: defconf drop invalid" connection-state=invalid
add action=drop chain=forward comment="38636-ALL: defconf drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=OutToWAN
add action=drop chain=input comment="38636-ALL: drop all INPUT (WAN)" in-interface=OutToWAN log=yes log-prefix=Drop_Input_WAN
add action=drop chain=forward comment="38636-ALL: drop all FORWARD (WAN)" in-interface=OutToWAN log=yes log-prefix=Drop_Forward_WAN
add action=drop chain=forward comment="38636-30/24: deny all to WAN" out-interface=OutToWAN src-address=30.0.0.0/24
add action=drop chain=forward comment="38636-30/24: deny all to GUEST/INTERNAL" dst-address-list=38636-30/24 out-interface=bridge src-address=30.0.0.0/24
add action=drop chain=forward comment="38636-20/24: drop all GST hardwire traffic to RST" dst-address=10.0.0.0/24 out-interface=bridge src-address-list=hardwire-block
add action=drop chain=forward comment="PPP: drop all FORWARD from VPN" in-interface=all-ppp log-prefix=VPNdrop
add action=drop chain=input comment="PPP: drop all INPUT from VPN" in-interface=all-ppp log-prefix=VPNdrop
# guestbridge not ready
add action=drop chain=forward comment="GUEST: Deny all to primary network" dst-address=10.0.0.0/24 in-interface=*F src-address=20.0.0.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface=OutToWAN
add action=dst-nat chain=dstnat comment="HTTPS PASSWORD 1000" dst-port=1000 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.2 to-ports=1000
add action=dst-nat chain=dstnat comment="PLEX PORT 32400 TCP" dst-port=32400 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.27 to-ports=32400
add action=dst-nat chain=dstnat comment="EMBY PORT 8096 TCP" dst-port=8096 in-interface=OutToWAN protocol=tcp to-addresses=30.0.0.50 to-ports=8096
add action=dst-nat chain=dstnat comment="MDM PORT 9383" dst-port=9383 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.10 to-ports=9383
add action=dst-nat chain=dstnat comment=P0019DEREK-PLEX dst-port=26555 in-interface=OutToWAN protocol=tcp to-addresses=30.0.0.40 to-ports=32400
add action=dst-nat chain=dstnat comment="HTTP WEBHUB TRAFFIC 80" dst-port=80 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.39 to-ports=80
add action=dst-nat chain=dstnat comment="HTTPS WEBHUB TRAFFIC 443" dst-port=443 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.2 to-ports=443
add action=dst-nat chain=dstnat comment="HTTPS PASSWORD 1000" dst-port=1000 in-interface=all-ethernet protocol=tcp to-addresses=10.0.0.2 to-ports=1000
add action=dst-nat chain=dstnat comment="SECURITY CAMERA SYSTEM 8081" dst-port=8081 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.28 to-ports=8081
add action=dst-nat chain=dstnat comment="HTTPS MAILTRAIN 3000" dst-port=3000 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.34 to-ports=3000
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47984 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=47984
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47989 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=47989
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48010 in-interface=OutToWAN protocol=tcp to-addresses=10.0.0.51 to-ports=48010
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47998 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=47998
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=47999 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=47999
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48000 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48000
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48002 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48002
add action=dst-nat chain=dstnat comment="MOONLIGHT - JORDAN PC" disabled=yes dst-port=48010 in-interface=OutToWAN protocol=udp to-addresses=10.0.0.51 to-ports=48010
/ip firewall service-port
set ftp ports=212
/ip ipsec identity
add generate-policy=port-override peer=peer1 remote-id=ignore
/ip route
add distance=1 gateway=**REMOVED**
add distance=1 dst-address=10.0.1.0/24 gateway=reichnet-8794
add distance=1 dst-address=10.0.2.0/24 gateway=reichnet-3978
add distance=1 dst-address=172.16.0.0/24 gateway=bridge
/ip service
set telnet disabled=yes
set ftp disabled=yes port=212
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip traffic-flow
set cache-entries=128k enabled=yes
/ip traffic-flow target
add dst-address=10.0.0.33
/ip upnp
set enabled=yes
/ppp aaa
set use-radius=yes
/ppp secret
add local-address=172.16.0.1 name=8794 profile=VPN-L2TP remote-address=172.16.0.240 service=l2tp
add local-address=172.16.0.1 name=3978 profile=VPN-L2TP remote-address=172.16.0.242 service=l2tp
add local-address=172.32.0.1 name=admin_bypass remote-address=172.32.0.100 service=l2tp
/radius
add address=10.0.0.5 realm=reichnetwork service=ppp,login,ipsec src-address=10.0.0.1
/snmp
set enabled=yes
/system clock
set time-zone-name=America/Los_Angeles
/system identity
set name=ReichHub
/system logging
add disabled=yes topics=ipsec
add topics=sstp
/system note
set note="ReichNet - Authorized administrators only. Access to this device is monitored."
/system package update
set channel=long-term
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/user aaa
set use-radius=yes
[38636@ReichHub] >

A new error also popped up on the end in the transfer box

transfer-newerror.png
I will still say that once I hit ‘retry’ the process continued and continues to hold in the 40 range which is still an improvement over before. But the errors and lack of full transfer speeds seem to indicate something else is creating a problem. Thanks again for everyone’s help on this!