Strange peaks in traffic

Hi

We have a 10Gbps link running between a RB1016+ and a HP switch. There is random spikes in traffic every minute or so too both the SFP+ and to a 1036 on a normal SFP port. i.e these spikes are not limited to just the SFP+ port. It actually seems to be across the entire Mikrotik switch. The packets per second increase from around 20000 to over 1 million. The traffic also goes over the limit of the interface e.g 20Gbps on a SFP+ port and over 15Gbps on a normal SFP port. Even some other SFP ports - the traffic would usually be around 20-30mbs increases for a few seconds to 200 or 300mbps.

These spikes last a few seconds, increases CPU etc, and then normal traffic continues.

Please see the picture.
westlake.png
However if I torch the traffic, it does not pick up these random traffic spikes? I have upgraded ROS to the latest stable and the latest firmware - this has not helped. This is causing some strange issues for us, e.g camera quality of streams etc. Any suggestions?

When you use torch, are the traffic spikes not seen or are they suddenly gone?

Not seen at all which is strange. I run a torch with an entry timeout of 5min, nothing untoward in the torch - nothing to explain the > 1000% increase in traffic and packets. I am running a torch on the interface and looking at the interface traffic graph, the spikes do no show up in the torch. The CPU usage does spike as well when there are these spikes.

It is almost like a flood of dummy traffic across the connected interfaces. I am also not seeing the traffic on the other side, e.g on the other Mikrotik or switch - i.e does not originate from them.

I am thinking this must be hardware related. CPU usage also spikes for no reason. There is no major config on this router. No PPPoE or firewall rules. Just a couple OSPF interfaces, few vlans etc.
cpu2.png

In your place i would try to:

  • check all bridges if they have admin-mac correctly set
  • temporarily disable fastpath/track (torch docet)
  • check interfaces status up/down counters
  • try to disable interface flow control

Could you show us the /export ? (opportunely obfuscated)

I am going to swap out the router with an exact copy (manual config i.e not export import) today. Will let you know.

router swapped out with a new 1016 with the exact same config. Working 100% now. Going to have a look at the old 1016 and see if there is a fault after a netinstall.
new.png

Have you upgraded many times (RC version included) that 1016 ? ..a couple of times I’ve experienced some problems when I did lot of uprade (testing boards) . Netinstall solved.
Let us know

Nope, just a few upgrades of the stable versions. Will check that router out this week.