Community discussions

MikroTik App
 
Nemesiz
just joined
Topic Author
Posts: 5
Joined: Mon Mar 04, 2013 9:35 pm

CCR1016-12G and a lot of pps

Thu Mar 07, 2013 9:33 am

Hi,

I`m interesting in CCR1016-12G model and have few question about it.
First of all I have some problems with DDOS. Situation is like this:

Attackers comes from unique IP address and normally 100k-400k pps ~50mbps. Sometime pps jumps to 1m. Every IP sends only 1 packet for initialize new connection. So it looks like big part of the world are trying to say hello to me :lol:
I had installed RouterOS (demo mode) on x86 system and made some screen shots.
1.png
Sometime load jumps to 400 mbps
2.png
The problem is IRQ load. At this type of attack Internet is just cut out. RPS likely is turned on. But the first Ethernet port IRQ works only on one core. x86 system problem ?

Does CCR1016-12G can handle it? Does it have no problem with IRQ load balancing? Or maybe enough to have RB1100Hx2?
You do not have the required permissions to view the files attached to this post.
 
Nemesiz
just joined
Topic Author
Posts: 5
Joined: Mon Mar 04, 2013 9:35 pm

Re: CCR1016-12G and a lot of pps

Sun Mar 10, 2013 1:33 pm

CCR 1016-12G - bridge eth2 and eth3 ports. Firewall with 28 rules (5 actives on attack). 600,000 pps, 250 mbps, cpu 100%, rps active on eth2. Profile shows firewall active at 95%. Need more power.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26968
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: CCR1016-12G and a lot of pps

Mon Mar 11, 2013 9:26 am

CCR 1016-12G - bridge eth2 and eth3 ports. Firewall with 28 rules (5 actives on attack). 600,000 pps, 250 mbps, cpu 100%, rps active on eth2. Profile shows firewall active at 95%. Need more power.
depending on what kind of rules you have. we plan to bring massive firewall performance upgrade for the CCR in one of the next RouterOS versions