I ran into the first problem. Following setup
CRS317
Using a bridge, as you need to with the CRS3xx series, with vlan-filtering.
Code: Select all
/interface bridge
add name=bridge1 protocol-mode=none vlan-filtering=yes
/interface bridge port
add bridge=bridge1 interface=sfp-sfpplus2 pvid=123
add bridge=bridge1 interface=sfp-sfpplus4
add bridge=bridge1 interface=sfp-sfpplus5
add bridge=bridge1 interface=sfp-sfpplus6
add bridge=bridge1 interface=sfp-sfpplus7
add bridge=bridge1 interface=sfp-sfpplus8
add bridge=bridge1 interface=sfp-sfpplus9
add bridge=bridge1 interface=sfp-sfpplus10
add bridge=bridge1 interface=sfp-sfpplus11
add bridge=bridge1 interface=sfp-sfpplus12
add bridge=bridge1 interface=sfp-sfpplus13
add bridge=bridge1 interface=sfp-sfpplus14
add bridge=bridge1 interface=sfp-sfpplus15
add bridge=bridge1 interface=sfp-sfpplus16 pvid=13
add bridge=bridge1 edge=yes frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=sfp-sfpplus3 pvid=13
/interface bridge vlan
add bridge=bridge1 tagged=bridge1,sfp-sfpplus16 untagged=sfp-sfpplus1,sfp-sfpplus2 vlan-ids=123
add bridge=bridge1 tagged=bridge1 untagged=sfp-sfpplus3,sfp-sfpplus16 vlan-ids=13
vlan inteface on top of the bridge
Code: Select all
/interface vlan
add interface=bridge1 name=vlan13 vlan-id=13
add interface=bridge1 name=vlan123 vlan-id=123
simple Fast track configured.
Code: Select all
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=established,related
add action=accept chain=forward connection-state=established,related
When traffic is flowing from vlan13 ( host at port sfp-sfpplus3 ) towards the network on sfp-sfpplus1 ( not bridged, no vlan ) it's not fasttracked
Although the connection is marked as fasttracked. But the bytecounter of the fasttrack dummy rule is not increasing.
The CPU is hitting 100% ( one core ) at ~500mbit/s
Traffic the other way around is fasttracked as expected. 1Gbit/s linespeed and CPU Is far away from 100%
It seems the problem is traffic coming in on a vlan interface on top of a bridge.
Is this a known limitation? And if so, why?