We have a CCR2216 device and Bonding, BGP is used in our device. Fasttrack is active. Our active traffic is around 15Gbps and CPU is over 70%. I'm posting the main settings on the device below. Can you help with the cause and solution?
Code: Select all
/interface bridge
add name=NASBridge
/interface ethernet
set [ find default-name=sfp28-1 ] auto-negotiation=no name=sfp-sfpplus1 \
speed=10Gbps
set [ find default-name=sfp28-2 ] auto-negotiation=no comment=CCR02 name=\
sfp-sfpplus2 speed=10Gbps
set [ find default-name=sfp28-3 ] auto-negotiation=no comment=CCR03 \
speed=10Gbps
set [ find default-name=sfp28-4 ] auto-negotiation=no comment=CCR04 \
speed=10Gbps
set [ find default-name=sfp28-5 ] auto-negotiation=no comment=CCR05 \
speed=10Gbps
set [ find default-name=sfp28-6 ] auto-negotiation=no comment=CCR06 \
speed=10Gbps
set [ find default-name=sfp28-7 ] auto-negotiation=no comment=CCR07 \
speed=10Gbps
set [ find default-name=sfp28-11 ] auto-negotiation=no comment=\
Internet1_Bonding speed=10Gbps
set [ find default-name=sfp28-12 ] auto-negotiation=no comment=\
Internet2_Bonding speed=10Gbps
/interface vlan
add interface=sfp-sfpplus2 name=NasVlan2 vlan-id=301
add interface=sfp28-3 name=NasVlan3 vlan-id=301
add interface=sfp28-4 name=NasVlan4 vlan-id=301
add interface=sfp28-5 name=NasVlan5 vlan-id=301
add interface=sfp28-6 name=NasVlan6 vlan-id=301
add interface=sfp28-7 name=NasVlan7 vlan-id=301
/interface bonding
add mode=802.3ad name=TT_Bonding slaves=sfp28-12,sfp28-11 \
transmit-hash-policy=layer-2-and-3
/interface vlan
add interface=TT_Bonding name=TT_VlanBonding vlan-id=302
/interface ethernet switch
set 0 l3-hw-offloading=yes
/routing bgp template
set default as=xxxxx disabled=no routing-table=main
/interface bridge port
add bridge=NASBridge interface=NasVlan3
add bridge=NASBridge interface=NasVlan4
add bridge=NASBridge interface=NasVlan5
add bridge=NASBridge interface=NasVlan6
add bridge=NASBridge interface=NasVlan7
add bridge=NASBridge interface=NasVlan2
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set rp-filter=loose tcp-syncookies=yes
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=\
established,related hw-offload=yes
add action=accept chain=forward connection-state=established,related
/routing bgp connection
add address-families=ip as=xxxx connect=yes disabled=no listen=yes \
local.address=x.x.x.x .role=ebgp multihop=yes name=BGP \
output.network=bgp_network remote.address=x.x.x.x/32 .as=xxxx \
router-id=x.x.x.x routing-table=main
/routing filter community-list
add communities=9121:666 disabled=no list=set1
/routing filter rule
add chain="" disabled=no rule=""