I'm having trouble receiving full gigabit on my RB3011UiAS in router mode and the speed fluctautes a lot, so results can be around 100-700Mbps less than expected.
On the other hand when I plug my laptop into my ISP router directly I get full gigabit wire speed.
Are there anything settings in my configuration that stands out wrong?
Kind regards,
Code: Select all
[oats@MikroTik] > export
# jan/29/2022 05:13:57 by RouterOS 6.49.2
#
# model = RouterBOARD 3011UiAS
/interface bridge
add admin-mac=64:D1:54:F5:10:B9 auto-mac=no comment=LAN name=bridge
/interface ethernet
set [ find default-name=ether1 ] advertise=1000M-full comment=WAN1-ISP1 l2mtu=8156 loop-protect=off mac-address=64:D1:54:F5:10:B5 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether2 ] advertise=1000M-full comment=WAN2-ISP2 l2mtu=8156 loop-protect=off mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether3 ] l2mtu=8156 loop-protect=on mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether4 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether5 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether6 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether7 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether8 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether9 ] l2mtu=8156 mtu=8156 rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=ether10 ] advertise=1000M-full l2mtu=8156 mtu=8156 poe-out=off rx-flow-control=auto speed=100Mbps tx-flow-control=auto
set [ find default-name=sfp1 ] advertise=1000M-full,2500M-full disabled=yes l2mtu=8158 mtu=8158 rx-flow-control=auto tx-flow-control=auto
/interface pppoe-client
add add-default-route=yes default-route-distance=2 disabled=no interface=ether2 max-mru=1508 max-mtu=1508 name=pppoe-out1 password=xxxxxxxx user=xxxxxxxx
/interface vlan
/interface ethernet switch
set 0 cpu-flow-control=no
set 1 cpu-flow-control=no
/interface list
add exclude=dynamic name=discover
add name=mactel
add name=mac-winbox
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp ranges=192.168.1.10-192.168.1.254
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge lease-time=1d name=dhcp1
/ppp profile
set *FFFFFFFE local-address=192.168.1.80 remote-address=dhcp
/snmp community
set [ find default=yes ] addresses=0.0.0.0/0
/user group
set full policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web,sniff,sensitive,api,romon,dude,tikapp
/interface bridge port
add bridge=bridge disabled=yes interface=ether2
add bridge=bridge interface=ether6
add bridge=bridge hw=no interface=sfp1
add bridge=bridge interface=ether4
add bridge=bridge interface=ether5
add bridge=bridge interface=ether7
add bridge=bridge interface=ether8
add bridge=bridge interface=ether9
add bridge=bridge interface=ether10
add bridge=bridge disabled=yes interface=ether1
add bridge=bridge interface=ether3 tag-stacking=yes
/ip neighbor discovery-settings
set discover-interface-list=discover
/interface detect-internet
set detect-interface-list=WAN internet-interface-list=WAN lan-interface-list=LAN wan-interface-list=WAN
/interface list member
add interface=ether2 list=discover
add interface=ether3 list=discover
add interface=ether4 list=discover
add interface=ether5 list=discover
add interface=sfp1 list=discover
add interface=ether6 list=discover
add interface=ether7 list=discover
add interface=ether8 list=discover
add interface=ether9 list=discover
add interface=ether10 list=discover
add interface=bridge list=discover
add interface=pppoe-out1 list=discover
add interface=vlan1 list=discover
add interface=bridge list=mac-winbox
add interface=ether2 list=mactel
add interface=ether3 list=mactel
add interface=ether4 list=mactel
add interface=ether5 list=mactel
add interface=ether6 list=mactel
add interface=ether7 list=mactel
add interface=ether8 list=mactel
add interface=ether9 list=mactel
add interface=ether10 list=mactel
add interface=bridge list=mactel
add interface=pppoe-out1 list=WAN
add interface=ether1 list=WAN
add interface=bridge list=LAN
add list=WAN
/ip address
add address=192.168.1.1/24 interface=bridge network=192.168.1.0
/ip dhcp-client
# DHCP client can not run on slave interface!
add disabled=no interface=sfp1
add disabled=no interface=ether1
/ip dhcp-server lease
/ip dhcp-server network
add address=192.168.1.0/24 dns-server=192.168.1.1 gateway=192.168.1.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,4.4.4.4 use-doh-server=https://dns.google/dns-query verify-doh-cert=yes
/ip dns static
/ip firewall address-list
add address=192.168.1.0/24 list=LAN
/ip firewall filter
add action=fasttrack-connection chain=forward comment=fasttrack connection-state=established,related
add action=accept chain=forward comment="allow related" connection-state=related
add action=drop chain=forward comment="drop invalid" connection-state=invalid protocol=tcp
add action=accept chain=input comment="accept established, related, untracked" connection-state=established,related,untracked
add action=drop chain=input comment="drop all not coming from LAN" in-interface-list=!LAN
add action=drop chain=forward comment="block outbound SMB traffic" dst-port=445 out-interface-list=WAN protocol=tcp
add action=drop chain=forward comment="block outbound SMB traffic" dst-port=445 out-interface-list=WAN protocol=udp
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" out-interface-list=WAN
/ip route
add check-gateway=ping distance=1 gateway=ether1 routing-mark=WAN1-ISP1
add check-gateway=ping distance=2 gateway=pppoe-out1 routing-mark=WAN2-ISP2
/ip service
set telnet address=192.168.1.0/24
set ftp address=192.168.1.0/24
set www address=192.168.1.0/24 port=8080
set ssh address=192.168.1.0/24
set www-ssl address=192.168.1.0/24 certificate=webcert disabled=no port=8443
set api address=192.168.1.0/24
set winbox address=192.168.1.0/24 port=58291
set api-ssl address=192.168.1.0/24
/ip upnp interfaces
add interface=ether1 type=external
add interface=bridge type=internal
/lcd
set default-screen=stats-all time-interval=hour
/ppp secret
add name=aa password=aa profile=default-encryption
/system clock
set time-zone-name=America/Toronto
/system leds
set 0 disabled=yes
/system logging
set 0 topics=info,!dhcp
/system routerboard settings
set silent-boot=yes
/tool bandwidth-server
set enabled=no
/tool graphing resource
add
/tool mac-server
set allowed-interface-list=mactel
/tool mac-server mac-winbox
set allowed-interface-list=mac-winbox