Right now all packets between VLANs (and access ports towards your CHR) are passing CRS’ weak CPU.
You should reconfigure CRS to use single bridge and vlan-filtering … you can have a look at this fine tutorial.
Your CRS3xx will then deal with VLANs in hardware (switch chip).
Now I have my transit upstreams connected directly to the CHR. Tomorrow I will try with one of them to pass it through the switch.
I suppose I can create a new bridge? Or do I have to use a single bridge to take advantage of HW acceleration?
Manual says that only single bridge can be HW offloaded … so you better stick to single bridge and use whatever means available to partition switch (either use VLANs with access ports or port isolation … the later being switch chip feature which brings you back to a mix of bridge and HW setup)
I’ve created the isolated ports and a unique bridge.
I’ve connected my upstreams (3 x FULL BGP) and all the traffic is working fine.
The bridge is returning “HW Offload” active on all ports.
And the CPU on the CRS is less 1-5% every time.
Many thanks! @mkx Please, send me a PM with your Paypal account to send you a gift.