Today I have changed one CRS317 to CCR1016-12S-1S+ to check whether the issue is on device itself or it's because of my configuration.
Here is my configuration.
/caps-man channel
add band=2ghz-g/n frequency=2412,2437,2462 name=Channels2.4Ghz tx-power=23
add band=5ghz-n/ac extension-channel=Ceee name=Channels5Ghz tx-power=25
add band=2ghz-g/n frequency=2412,2437,2462 name=Channels2.4Ghz_HighTx \
tx-power=28
add band=5ghz-n/ac extension-channel=Ceee name=Channels5Ghz_HighTx tx-power=\
28
/caps-man datapath
add name=WiFi_Data vlan-id=20 vlan-mode=use-tag
add client-to-client-forwarding=yes name=WiFi_Office vlan-id=10 vlan-mode=\
use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=WiFi_Guest \
vlan-id=20 vlan-mode=use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=WiFi_Office_1 \
vlan-id=10 vlan-mode=use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=NS2 vlan-id=60 \
vlan-mode=use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=NS3 vlan-id=70 \
vlan-mode=use-tag
/caps-man configuration
add channel=Channels2.4Ghz country="united states" datapath=NS2 hide-ssid=yes \
installation=any mode=ap name=Config_NS2_2.4Ghz ssid=Hottab
add channel=Channels2.4Ghz country="united states" datapath=NS3 hide-ssid=yes \
installation=any mode=ap name=Config_NS3_2.4Ghz ssid=Hottab
/interface bridge
add name=Loopback
add igmp-snooping=yes name=bridge1 priority=0x1000 protocol-mode=mstp \
region-name=CS region-revision=1 vlan-filtering=yes
/interface vlan
add interface=bridge1 name=CAMERA_30 vlan-id=30
add interface=bridge1 name=LAN_10 vlan-id=10
add interface=bridge1 name=LOA_50 vlan-id=50
add interface=bridge1 name=MGMT_99 vlan-id=99
add interface=bridge1 name=NS2_60 vlan-id=60
add interface=bridge1 name=NS3_70 vlan-id=70
add interface=bridge1 name=TEL_40 vlan-id=40
add interface=bridge1 name=WIFI_20 vlan-id=20
/interface vrrp
add interface=CAMERA_30 name=VRRP_CAMERA_30 priority=105 vrid=30
add interface=LAN_10 name=VRRP_LAN_10 priority=105 vrid=10
add interface=LOA_50 name=VRRP_LOA_50 priority=105 vrid=50
add interface=MGMT_99 name=VRRP_MGMT_99 priority=105 vrid=99
add interface=NS2_60 name=VRRP_NS2_60 priority=105 vrid=60
add interface=NS3_70 name=VRRP_NS3_70 priority=105 vrid=70
add interface=TEL_40 name=VRRP_TEL_40 priority=105 vrid=40
add interface=WIFI_20 name=VRRP_WIFI_20 preemption-mode=no vrid=20
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm name=WiFi_Sec \
passphrase=avana@123
/caps-man configuration
add country="viet nam" datapath=WiFi_Data mode=ap name=WiFi_Config security=\
WiFi_Sec ssid="Avana Retreat"
add channel.control-channel-width=20mhz country="viet nam" datapath=\
WiFi_Guest mode=ap name=WiFi_Guest security=WiFi_Sec ssid="Avana Retreat"
add country="viet nam" datapath=WiFi_Office_1 mode=ap name=WiFi_Office_1 \
security=WiFi_Sec ssid="Avana Retreat"
add channel=Channels5Ghz country="united states" datapath=NS2 installation=\
any mode=ap name=WiFi_NS2_5Ghz security=WiFi_Sec ssid="Avana Retreat"
add channel=Channels5Ghz country="united states" datapath=NS3 installation=\
any mode=ap name=WiFi_NS3_5Ghz security=WiFi_Sec ssid="Avana Retreat"
add channel=Channels2.4Ghz country="united states" datapath=WiFi_Guest \
installation=any mode=ap name=Config_Guest_2.4Ghz security=WiFi_Sec ssid=\
"Avana Retreat"
add channel=Channels5Ghz country="united states" datapath=WiFi_Guest \
installation=any mode=ap name=Config_Guest_5Ghz security=WiFi_Sec ssid=\
"Avana Retreat"
add channel=Channels2.4Ghz_HighTx country="united states" datapath=WiFi_Guest \
installation=any mode=ap name=Config_Guest_2.4Ghz_HighTx security=\
WiFi_Sec ssid="Avana Retreat"
add channel=Channels5Ghz_HighTx country="united states" datapath=WiFi_Guest \
installation=any mode=ap name=Config_Guest_5Ghz_HighTx security=WiFi_Sec \
ssid="Avana Retreat"
add channel=Channels2.4Ghz country="united states" datapath=WiFi_Office_1 \
installation=any mode=ap name=Config_Office_2.4Ghz security=WiFi_Sec \
ssid="Avana Retreat"
add channel=Channels5Ghz country="united states" datapath=WiFi_Office_1 \
installation=any mode=ap name=Config_Office_5Ghz security=WiFi_Sec ssid=\
"Avana Retreat"
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=dhcp_pool0 ranges=172.16.10.20-172.16.10.250
add name=dhcp_pool1 ranges=172.16.20.20-172.16.21.250
add name=dhcp_pool2 ranges=172.16.30.20-172.16.30.250
add name=dhcp_pool3 ranges=172.16.40.20-172.16.40.100
add name=dhcp_pool4 ranges=172.16.99.50-172.16.99.70
add name=dhcp_pool5 ranges=172.16.50.20-172.16.50.250
add name=dhcp_pool10 ranges=172.16.60.100-172.16.60.200
add name=dhcp_pool11 ranges=172.16.70.100-172.16.70.200
/ip dhcp-server
add address-pool=dhcp_pool0 disabled=no interface=VRRP_LAN_10 lease-time=4h \
name=dhcp1
add address-pool=dhcp_pool1 authoritative=after-10sec-delay disabled=no \
interface=VRRP_WIFI_20 lease-time=4h name=dhcp2
add address-pool=dhcp_pool2 disabled=no interface=VRRP_CAMERA_30 lease-time=\
4h name=dhcp3
add address-pool=dhcp_pool3 disabled=no interface=VRRP_TEL_40 lease-time=8h \
name=dhcp4
add address-pool=dhcp_pool4 disabled=no interface=VRRP_MGMT_99 lease-time=4h \
name=dhcp5
add address-pool=dhcp_pool5 disabled=no interface=VRRP_LOA_50 lease-time=4h \
name=dhcp6
add address-pool=dhcp_pool10 disabled=no interface=VRRP_NS2_60 lease-time=3h \
name=dhcp7
add address-pool=dhcp_pool11 disabled=no interface=VRRP_NS3_70 lease-time=4h \
name=dhcp8
/routing ospf instance
set [ find default=yes ] router-id=4.4.4.4
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=Config_Guest_5Ghz \
name-format=identity name-prefix=WF-NhaSoNV-1-2 radio-mac=\
C4:AD:34:FA:4A:35
add action=create-dynamic-enabled master-configuration=Config_Guest_2.4Ghz \
name-format=identity name-prefix=WF-NhaSo19.2-1 radio-mac=\
C4:AD:34:FA:62:C7
/interface bridge msti
add bridge=bridge1 identifier=2 priority=0x2000 vlan-mapping=20
add bridge=bridge1 identifier=1 priority=0x1000 vlan-mapping=\
10,30,40,99,50,60,70
/interface bridge port
add bridge=bridge1 interface=sfp-sfpplus3
add bridge=bridge1 interface=sfp-sfpplus4
add bridge=bridge1 interface=sfp-sfpplus5
add bridge=bridge1 interface=sfp-sfpplus6
add bridge=bridge1 interface=sfp-sfpplus7
add bridge=bridge1 interface=sfp-sfpplus8
add bridge=bridge1 interface=sfp-sfpplus9
add bridge=bridge1 interface=sfp-sfpplus10
add bridge=bridge1 interface=sfp-sfpplus11
add bridge=bridge1 interface=sfp-sfpplus12
add bridge=bridge1 interface=sfp-sfpplus13
add bridge=bridge1 interface=sfp-sfpplus14
add bridge=bridge1 interface=sfp-sfpplus15
add bridge=bridge1 interface=sfp-sfpplus16
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface bridge vlan
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=99
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=20
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=30
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=10
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=40
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=50
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=60
add bridge=bridge1 tagged="bridge1,sfp-sfpplus3,sfp-sfpplus4,sfp-sfpplus5,sfp-\
sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus10,sfp-sfpplus1\
1,sfp-sfpplus12,sfp-sfpplus13,sfp-sfpplus14,sfp-sfpplus15,sfp-sfpplus16" \
vlan-ids=70
/ip address
add address=172.16.10.2/24 interface=LAN_10 network=172.16.10.0
add address=172.16.99.2/24 interface=MGMT_99 network=172.16.99.0
add address=172.16.20.2/23 interface=WIFI_20 network=172.16.20.0
add address=172.16.30.2/24 interface=CAMERA_30 network=172.16.30.0
add address=172.16.40.2/24 interface=TEL_40 network=172.16.40.0
add address=172.16.2.2/24 interface=sfp-sfpplus1 network=172.16.2.0
add address=172.16.3.2/30 interface=sfp-sfpplus2 network=172.16.3.0
add address=172.16.10.1 interface=VRRP_LAN_10 network=172.16.10.1
add address=172.16.20.1 interface=VRRP_WIFI_20 network=172.16.20.1
add address=172.16.30.1 interface=VRRP_CAMERA_30 network=172.16.30.1
add address=172.16.40.1 interface=VRRP_TEL_40 network=172.16.40.1
add address=172.16.99.1 interface=VRRP_MGMT_99 network=172.16.99.1
add address=172.16.50.2/24 interface=LOA_50 network=172.16.50.0
add address=172.16.50.1 interface=VRRP_LOA_50 network=172.16.50.1
add address=172.16.60.2/24 interface=NS2_60 network=172.16.60.0
add address=172.16.60.1 interface=VRRP_NS2_60 network=172.16.60.1
add address=172.16.70.1 interface=VRRP_NS3_70 network=172.16.70.1
add address=172.16.70.2/24 interface=NS3_70 network=172.16.70.0
add address=4.4.4.4 interface=Loopback network=4.4.4.4
/ip dhcp-server network
add address=172.16.10.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.10.1
add address=172.16.20.0/23 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.20.1
add address=172.16.30.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.30.1
add address=172.16.40.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.40.1
add address=172.16.50.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.50.1
add address=172.16.60.0/24 gateway=172.16.60.1
add address=172.16.70.0/24 gateway=172.16.70.1
add address=172.16.99.0/24 dns-server=8.8.8.8,8.8.4.4 gateway=172.16.99.1
/ip dns
set servers=8.8.8.8
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/routing ospf interface
add cost=100 interface=sfp-sfpplus2 network-type=broadcast
add cost=100 interface=CAMERA_30 network-type=broadcast
add cost=100 interface=LAN_10 network-type=broadcast
add cost=100 interface=MGMT_99 network-type=broadcast
add cost=100 interface=TEL_40 network-type=broadcast
add cost=100 interface=WIFI_20 network-type=broadcast
add cost=100 interface=VRRP_WIFI_20 network-type=broadcast
add cost=100 interface=LOA_50 network-type=broadcast
add cost=100 interface=NS2_60 network-type=broadcast
add cost=100 interface=NS3_70 network-type=broadcast
/routing ospf network
add area=backbone network=172.16.2.0/24
add area=backbone network=172.16.3.0/30
add area=backbone network=172.16.10.0/24
add area=backbone network=172.16.20.0/23
add area=backbone network=172.16.30.0/24
add area=backbone network=172.16.40.0/24
add area=backbone network=172.16.99.0/24
add area=backbone network=172.16.50.0/24
add area=backbone network=172.16.60.0/24
add area=backbone network=172.16.70.0/24
add area=backbone network=4.4.4.4/32
/system clock
set time-zone-name=Asia/Bangkok
/system identity
set name=CORE_SW01
/system logging
set 0 topics=info,!caps,!dhcp
add action=disk topics=warning
/system package update
set channel=long-term
/system routerboard settings
set boot-os=router-os
/system scheduler
add interval=3s name=schedule1 on-event=":if ([ /system resource get cpu-load]\
>95) do={ \r\
\n\t:log warning \"Reboot for 100% CPU\";\r\
\n\t}" policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=apr/14/2021 start-time=12:25:11
I have written a script to check when CPU is full and noticed It almost happens from 8pm to 8am, sometime in day time also.