Community discussions

MikroTik App
 
sebasGST
just joined
Topic Author
Posts: 8
Joined: Fri Sep 06, 2019 6:41 pm

High CPU Load

Mon Apr 03, 2023 8:41 pm

Hello everyone, i recently have reports of my clients, intermitencies, slow speed. When i go to check the Mikrotik, i see thats a high cpu usage in two switches (different sites), im gona attach the file below of both switch, can you help me? Theres a bad config? I'm a bit new using VLAN in mikrotik. Thank you!
-----------------------------------------
SWITCH 1 INFO
"created from master port" name=bridge2 protocol-mode=none \
vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name=ether1/LANSW1 speed=100Mbps
set [ find default-name=ether2 ] disabled=yes name=ether2/MIMOSA_XXX speed=\
100Mbps
set [ find default-name=ether3 ] name="ether3/AP C5x XXX" speed=100Mbps
set [ find default-name=ether4 ] name=ether4/INTERNET_XXX speed=100Mbps
set [ find default-name=ether5 ] speed=100Mbps
set [ find default-name=ether6 ] speed=100Mbps
set [ find default-name=ether7 ] speed=100Mbps
set [ find default-name=ether8 ] speed=100Mbps
set [ find default-name=sfp9 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp10 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp11 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp12 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
/interface vlan
add interface=bridge2 name=vlan400 vlan-id=400
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge2 interface=ether2/MIMOSA_XXX
add bridge=bridge2 interface="ether3/AP C5x XXX"
add bridge=bridge2 interface=ether4/INTERNET_XXX
add bridge=bridge2 interface=ether5
add bridge=bridge2 interface=ether6
add bridge=bridge2 interface=ether7
add bridge=bridge2 interface=ether8
add bridge=bridge2 interface=ether1/LANSW1
/interface bridge vlan
add bridge=bridge2 tagged="ether1/LANSW1,ether2/MIMOSA_XXX,ether3/AP C5x XXX\
,bridge2,ether4/INTERNET_XXX" vlan-ids=400
add bridge=bridge2 tagged=\
"ether1/LANSW1,ether2/MIMOSA_XXX,ether3/AP C5x XXX" vlan-ids=100
add bridge=bridge2 tagged="ether1/LANSW1,ether3/AP C5x XXX" vlan-ids=\
99,359,183,182,388,443,137,65,200,148,405,448,185,186,330,443
/ip address
add address=10.50.51.XXX/23 interface=vlan400 network=10.50.50.0

--------------------------
SWITCH 2 INFO

/interface bridge
add name=bridge1 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name="ether1/ AP CC" speed=100Mbps
set [ find default-name=ether2 ] name="ether2/ PUENTE SW 201" speed=100Mbps
set [ find default-name=ether3 ] name="ether3/ AP MAN " speed=100Mbps
set [ find default-name=ether4 ] name="ether4/ AP PO" speed=100Mbps
set [ find default-name=ether5 ] name="ether5/ LIBRE" speed=100Mbps
set [ find default-name=ether6 ] name="ether6/ AP TU" speed=100Mbps
set [ find default-name=ether7 ] name="ether7/ LIBRE" speed=100Mbps
set [ find default-name=ether8 ] name=ether8/REP speed=100Mbps
set [ find default-name=sfp9 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp10 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp11 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
set [ find default-name=sfp12 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full disabled=yes
/interface vlan
add interface=bridge1 name=vlan36 vlan-id=36
add interface=bridge1 name=vlan99 vlan-id=99
add interface=bridge1 name=vlan100 vlan-id=100
add interface=bridge1 name=vlan200 vlan-id=200
add interface=bridge1 name=vlan401 vlan-id=401
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,passw\
ord,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge1 interface="ether1/ AP CC"
add bridge=bridge1 interface="ether2/ PUENTE SW 201"
add bridge=bridge1 interface="ether3/ AP MAN"
add bridge=bridge1 interface="ether4/ AP PO"
add bridge=bridge1 interface="ether5/ LIBRE"
add bridge=bridge1 interface="ether6/ AP TU" pvid=100
add bridge=bridge1 interface="ether7/ LIBRE"
add bridge=bridge1 interface=ether8/REPE pvid=100
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface bridge vlan
add bridge=bridge1 tagged="ether1/ AP C,ether7/ LIBRE,ether2/ PUENTE SW 20\
1,ether3/ AP MAN,ether4/ AP PO,bridge1" untagged=\
"ether8/REPE,ether6/ AP TU" vlan-ids=100
add bridge=bridge1 tagged=\
"ether2/ PUENTE SW 201,ether3/ AP MAN,ether4/ AP PO" \
vlan-ids=99
add bridge=bridge1 tagged="ether2/ PUENTE SW 201,ether4/ AP PO" \
vlan-ids=200,201
add bridge=bridge1 tagged="ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ AP M\
AN,ether4/ AP PO,ether5/ LIBRE,ether7/ LIBRE" vlan-ids=\
400
add bridge=bridge1 tagged="ether2/ PUENTE SW 201,ether4/ AP PO" \
vlan-ids=36,467,193,273,275,389,272,274,472,23,471,470,243,195,350,415
add bridge=bridge1 tagged="ether1/ AP CC,ether2/ PUENTE SW 201" vlan-ids=\
74
/interface ethernet switch egress-vlan-tag
add tagged-ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ A\
P MAN,ether4/ AP PORVENIR AKF,ether5/ LIBRE,ether7/ LIBRE" vlan-id=\
100
add tagged-ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ A\
P MAN,ether4/ AP PO,ether5/ LIBRE,ether6/ AP TU,eth\
er7/ LIBRE" vlan-id=99
add tagged-ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ A\
P MAN,ether4/ AP PO,ether5/ LIBRE,ether6/ AP TU,eth\
er7/ LIBRE" vlan-id=401
add tagged-ports="switch1-cpu,ether2/ PUENTE SW 201,ether4/ AP PO" \
vlan-id=36
add tagged-ports="switch1-cpu,ether2/ PUENTE SW 201,ether4/ AP PO" \
vlan-id=200
add tagged-ports="switch1-cpu,ether2/ PUENTE SW 201,ether4/ AP PO" \
vlan-id=201
/interface ethernet switch ingress-vlan-translation
add new-customer-vid=100 ports=ether8/REPE
add new-customer-vid=100 ports="ether6/ AP TU"
/interface ethernet switch vlan
add ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ AP MAN\
,ether4/ AP PO,ether5/ LIBRE,ether6/ AP TU,ether7/ LI\
BRE,ether8/REPE" vlan-id=100
add ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ AP MAN\
,ether4/ AP PO,ether5/ LIBRE,ether6/ AP TU,ether7/ LI\
BRE" vlan-id=99
add ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether3/ AP MAN\
,ether4/ AP PO,ether5/ LIBRE,ether6/ AP TU,ether7/ LI\
BRE,ether8/REPE" vlan-id=401
add ports="switch1-cpu,ether1/ AP CC,ether2/ PUENTE SW 201,ether4/ AP PO\
" vlan-id=36
/ip address
add address=10.100.10X.XXX/24 interface=vlan100 network=10.100.10X.0
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=\
established,related
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward connection-state=invalid
/system identity
set name="SW

Thank you all!

Regards
Sebastian G.
You do not have the required permissions to view the files attached to this post.
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12648
Joined: Thu Mar 03, 2016 10:23 pm

Re: High CPU Load

Mon Apr 03, 2023 9:21 pm

Which device model(s) are they?
 
sebasGST
just joined
Topic Author
Posts: 8
Joined: Fri Sep 06, 2019 6:41 pm

Re: High CPU Load

Mon Apr 03, 2023 9:36 pm

Which device model(s) are they?
Both are CRS112-8G-4S
 
User avatar
mkx
Forum Guru
Forum Guru
Posts: 12648
Joined: Thu Mar 03, 2016 10:23 pm

Re: High CPU Load

Mon Apr 03, 2023 9:40 pm

CRS1xx can not HW offload VLAN enabled bridge. You have to configure VLANs on switch chip. Use this help page for inspiration.
 
sebasGST
just joined
Topic Author
Posts: 8
Joined: Fri Sep 06, 2019 6:41 pm

Re: High CPU Load

Mon Apr 03, 2023 9:50 pm

CRS1xx can not HW offload VLAN enabled bridge. You have to configure VLANs on switch chip. Use this help page for inspiration.
Ok, i'll try to make changes, thanks for the help!

Who is online

Users browsing this forum: GoogleOther [Bot], mkx, tangent, woland and 33 guests