Layer 3 Hardware Offloading Mikrotik - Deep Dive

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 พ.ย. 2024

ความคิดเห็น • 75

  • @ronneldue3954
    @ronneldue3954 4 วันที่ผ่านมา

    your teaching is absolutely amazing. please don't stop creating great content like this one.

  • @Red1Wollip
    @Red1Wollip 8 หลายเดือนก่อน +2

    I am building my lab with a full Mikrotik stack. Your videos have been instrumental in my training and understanding the ins and outs of the Mikrotik world. I do wish to give you a very big THANK YOU fo your help an dclear presintation of methods and configurations.

  • @traininingbits-pg5dn
    @traininingbits-pg5dn 4 หลายเดือนก่อน

    You are simply the best Mikrotik trainer I have seen.

  • @mikkio5371
    @mikkio5371 ปีที่แล้ว +2

    Network trip . Did really well in ospf . He did extremely well on ospf . Respect to him on ospf as aswell as other lecture

  • @davidmooreii3092
    @davidmooreii3092 3 หลายเดือนก่อน +1

    Thanks! this was exactly the fix I was looking for. CPU stays under 35% most of the time now and I learned how to VLAN better!

  • @ronaldhaley6169
    @ronaldhaley6169 ปีที่แล้ว +2

    Thank you. Really happy to see this today. You are the best!!!!

  • @n8lbv
    @n8lbv 2 หลายเดือนก่อน +1

    You are doing a great job on these videos, thank you.
    Easy pace that I can follow and your points are memorable, meaning I can use them later!

  • @mnoquiao
    @mnoquiao 2 หลายเดือนก่อน +1

    all of your videoes are great and easy to understand ♥♥♥

  • @RaquelSanroque-o6j
    @RaquelSanroque-o6j หลายเดือนก่อน +2

    Great Tutorial!!! Do you always need a bridge created? if the CRS309 is acting as a router, Can I simply use L3HW-offload with IPs on the physical interfaces without using VLANs and without a bridge? Will L3HW-offload work that way?

    • @TheNetworkTrip
      @TheNetworkTrip  หลายเดือนก่อน

      Hello!
      That approach won’t offer full L3 hardware offloading. You will need to use fast track to have some of the traffic with hardware acceleration

    • @RaquelSanroque-o6j
      @RaquelSanroque-o6j หลายเดือนก่อน

      @@TheNetworkTrip Thanks for the quick reply, with this setup(no bridge) I see all routes with H flag for HW-Offload but the CPU is actually very high. I guess I'll have to change the config to bridge/vlan like you showed on the video.

  • @zauraliyev367a2
    @zauraliyev367a2 9 หลายเดือนก่อน +1

    Hi sir! Great tutorial.
    Will it work if I have only one interface for both up and downstream traffic?

  • @arebacollins
    @arebacollins 7 หลายเดือนก่อน

    Would be great to have a step by step NAT - using Fasttrack and firewall using Fasttrack guide.. with these, it almost seems inconceivable but, might one completely eliminate CCR's for CRS devices for doing most deployments? BGP?

  • @redrover06able
    @redrover06able 11 หลายเดือนก่อน +3

    I have a crs326. Configured hw offload with single bridge only. I see the "H" in the route list. But when I pass traffic, cpu stay very high (93%). It doesn't seem like HW offload is working. When I look at the vlan under bridge on the interface screen, I see traffic on the vlan instead of physical interface. Any suggestion?

  • @dvreshta
    @dvreshta ปีที่แล้ว +1

    Very well structured and well explained video.

  • @xtlmeth
    @xtlmeth ปีที่แล้ว +1

    Your videos are awesome. Thanks!

  • @snafu7777
    @snafu7777 10 หลายเดือนก่อน

    amazing. if im going to use my ccr2216 to bgp peer with my upstream provider, do i need follow exactly the same procedure?

  • @hermestarazona
    @hermestarazona 10 ชั่วโมงที่ผ่านมา

    Hi, Nice example. Can this be enabled on a CCR2216 as a border router against the ISP? Taking into account that this router has active BPG that is published to the internet

  • @Andrew_Thrift
    @Andrew_Thrift 6 หลายเดือนก่อน

    Great tutorial !
    Thanks Wilmer

  • @alimibrahem8120
    @alimibrahem8120 ปีที่แล้ว +1

    As always very thanksful Mr.Wilmer..! it was very informative..!
    But Question to ask: why you use VLAN in your LAB..? i mean why you didn't just use the physical interface and assigning IP to it without creating any VLAN..?

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว +2

      Hello Ali!
      That will force to use the CPU, if we want to take advantage of L3 hardware offloading we must use a bridge and Vlan interfaces.

  • @SergeantTrigger
    @SergeantTrigger ปีที่แล้ว +1

    Great content as always. Thanks!

  • @ronaldhaley6169
    @ronaldhaley6169 ปีที่แล้ว +1

    You mention that we can only have a single bridge, but you are using ospf here as well. You recommend using a loopback bridge in OSPF. So don't we end up with two bridges here?

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว

      Hello!
      Only one bridge will be using hardware offloading. You can add a loopback interface without any problems.

  • @zeljkomikrotik
    @zeljkomikrotik ปีที่แล้ว +1

    Hi and great video! Is it possible to use L3HW Offloading without OSPF? (i know, the routing must then be done manually)..

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว

      Hello!
      Yes, you can use static routing

  • @BudiSetiawan-id9en
    @BudiSetiawan-id9en ปีที่แล้ว +1

    Sir can explore more regarding mpls hardware offloading on mikrotik. I believe it only works on lates ccr 22xxx or 21xxx series

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว

      Thanks for the suggestion! I’ll create a class about it.

  • @Feed9Will
    @Feed9Will 9 หลายเดือนก่อน

    Just began exploring Mikrotik. Useful Vid! Heroic dose!
    Can you elaborate on HW offload for inter-vlan routing security? What performance penalty (CPU) on Switch ACLs vs IP firewall + Fastrack?
    I'm accustomed to L3 switch ACLs stateful TCP and stateless UDP. Can Mikrotik bridge / vlan int routing be full L4 stateful within the bridge / vlan interfaces. Or must go CPU?
    I have the packet flow documentation which I need to dive into more but the GNS3 routeros image lacks the switch chip / ACLs. Likely I need to buy switch to really demo Mikrotik L3 switching. Eyeing CRS326-24S+2Q+ vs CRS317-1G-16S+. CRS326-24S+2Q+ appears more designed toward L2 raw forwarding. CRS317-1G-16S+ appears more designed toward L3/4 given it has much more CPU.

  • @Gtechinfotech
    @Gtechinfotech ปีที่แล้ว +1

    Many thanks sir

  • @JaZzDeOliveira
    @JaZzDeOliveira ปีที่แล้ว +2

    Really good video

  • @umiseaz
    @umiseaz ปีที่แล้ว +1

    excellent tutorial ! thanks

  • @techknight1
    @techknight1 8 หลายเดือนก่อน

    How would you add a Management VLAN as well as romon and MAC telnet to this setup?

  • @techturboexplore
    @techturboexplore ปีที่แล้ว

    Is this applicable for Mpls/Vpls with Ospf case?

  • @sanjoyshaha3234
    @sanjoyshaha3234 ปีที่แล้ว +1

    Great! Is L3HW work on BGP routes?

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว +1

      Hello!
      Yeah, it does, it will offload up to 240k entries (CCR2216).

  • @mrfran1
    @mrfran1 ปีที่แล้ว +1

    It is worth activating it in a CCR 2116 acting as DHCP Server + CGNAT?

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว

      Hello! If you have high traffic and don't require mangle or VRFs, using it would be a great idea.

  • @arebacollins
    @arebacollins 7 หลายเดือนก่อน

    Would be interesting to see how those CPU counts look like when running tcp tests. UDP is very forgiving...

    • @TheNetworkTrip
      @TheNetworkTrip  7 หลายเดือนก่อน

      It should not impact the CPU because it does not it.

    • @arebacollins
      @arebacollins 7 หลายเดือนก่อน

      @@TheNetworkTrip I noticed the introduction of lo interface somewhere in the last couple of releases, it seems any IP configured on this interface is not offloaded. and if that is the IP your traffic hits to go through the router, CPU baby! I by default install a loopback address and advertise it passively as broadcast on ospf.

    • @TheNetworkTrip
      @TheNetworkTrip  7 หลายเดือนก่อน

      @@arebacollins All traffic going to the router will hit the CPU!! The traffic going to remote hosts will be offloaded

    • @arebacollins
      @arebacollins 7 หลายเดือนก่อน +1

      @@TheNetworkTrip then something must be amiss. I dont seem to be getting offloaded even with all the routes set up and marked as H

  • @Gabrielgful
    @Gabrielgful ปีที่แล้ว +1

    Very good video, everything explained clearly, I have been using several CRS305 with Hardware Offloading for a couple of months now, they are installed in micro pops, they have a WAN interface (where there is BGP to announce our prefixes) and a LAN interface where simply with a DHCP delivers the service, but I have problems limiting the speed, I used the "rate" function in Switch>Rule and it worked well but until certain traffic, I have noticed that after 1.5Gbps it starts to cause problems, for example on the WAN port It reaches 1.5Gbps and only 1.2Gbps is coming out of the LAN port, I deactivate the rule and at that moment both interfaces start to have 1.5. Could you help me with an idea of how I could effectively limit the service? taking into account that it was done in switch>rule since, being hierarchical, it first had a rule allowing ICMP not to be affected by saturation and avoid high times and packet losses (at least in that protocol). Thank you so much.

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว +1

      Hello!
      I'll create some videos about rate limiting on CRSXXX devices.

  • @alexv305
    @alexv305 3 หลายเดือนก่อน +1

    Does this work with the rb750gr3?

    • @TheNetworkTrip
      @TheNetworkTrip  หลายเดือนก่อน

      Hello!
      That model is not supported, just the ones shown on the video.

  • @arebacollins
    @arebacollins ปีที่แล้ว

    Would MPLS/VPLS work this way too?

  • @AlejandroMartinezHernandez-f8u
    @AlejandroMartinezHernandez-f8u 10 หลายเดือนก่อน +1

    Hi, i enable L3 Hw Offloading but this block navigation to internet on the vlans

    • @TheNetworkTrip
      @TheNetworkTrip  10 หลายเดือนก่อน +1

      Hi!
      Before enabling l3 hardware offloading, you must build the Vlan table and enable Vlan filtering as I explained in the video.
      Vlans should work without any problem.

    • @AlejandroMartinezHernandez-f8u
      @AlejandroMartinezHernandez-f8u 10 หลายเดือนก่อน +1

      Thanks!@@TheNetworkTrip in my case, get out ports with my "wans" of the bridge has the solved

    • @TheNetworkTrip
      @TheNetworkTrip  10 หลายเดือนก่อน +1

      @@AlejandroMartinezHernandez-f8u Removing the ports from the bridge will disable L3 hardware offloading in those interfaces. The ports should remain in the bridge, and manage all the IPs using vlan interfaces as I have shown in the video.

    • @AlejandroMartinezHernandez-f8u
      @AlejandroMartinezHernandez-f8u 9 หลายเดือนก่อน

      Thanks, yes! it was my mistake. Regarding this configuration, it is recommended to use ServerOpenVPN

  • @biki1973
    @biki1973 ปีที่แล้ว +1

    is it possible to hardware offload MPLS on those devices? P PE function? if so, are you planning to make video about it?

    • @TheNetworkTrip
      @TheNetworkTrip  ปีที่แล้ว

      I’ll complete some additional testing with MPLS VPNs and I’ll add a video about it

    • @biki1973
      @biki1973 ปีที่แล้ว

      @@TheNetworkTrip while you're at it, could you check if it's possible to hardware offload macsec on these chips ?

  • @arebacollins
    @arebacollins 7 หลายเดือนก่อน

    I have a question, in a scenario where you have multiple CRS310's and at the end of it a client device, assigning a /30 address on a vlan on the bridge in the last CRS310, tagging the vlan on the bridge and on the interface connected to a client mikrotik, and assigning a /31 IP address on the vlan and another on the customer mikrotik seems to break offload. Im getting 20% cpu on 65mbps. :-( am I missing something? ) all routes have the flag H in them.

  • @barma1309
    @barma1309 ปีที่แล้ว +1

    what happen with your blog - thenetworktrip ???

  • @arebacollins
    @arebacollins 7 หลายเดือนก่อน

    ccr2004 -16G-2S+ ? does it have l3hw like the 2116 ? cant see anything in the literature

    • @TheNetworkTrip
      @TheNetworkTrip  7 หลายเดือนก่อน

      Hello, no,it doesn’t. At the moment, the CCR2116 and CCR2216 are the only CCRs that support it (plus CRS 3xx and 5xx)

  • @rodrigosteinhorst624
    @rodrigosteinhorst624 2 หลายเดือนก่อน

    In the case of having two operators and only receiving default routes, would it work well for the BGP border?
    without a public IP on this BGP border

    • @TheNetworkTrip
      @TheNetworkTrip  2 หลายเดือนก่อน

      Hello!
      If all the routes are in the main table, yes. If not, only the main table will be hardware offloaded.

  • @kachetetv8958
    @kachetetv8958 10 หลายเดือนก่อน

    mano esto mismo pero en español por favor!