RB4011iGS+RM for my use case
Posted: Tue Jan 08, 2019 8:35 pm
I am going to be moving all Layer-3 switching off our trusty CRS-125 and turning it into a pure switch. To route, I am considering going with a new RB4011iGS+RM and have a few questions:
Seems that all firewall/NAT/routing is SW based with hw offload only for IPsec. The spec test results (https://mikrotik.com/product/rb4011igs_ ... estresults) indicate (based on packet size) 800k-5m pps with "routing none (fast path)", 800k-1m pps with "25 simple queries," and ~600k pps with "25 simple filter rules."
Finally, the assuming the RB4011iGS+RM is the edge router, is there any advantage in plugging each of the 6 access points into the RB4011iGS+RM directly vs. all traffic going to a downstream switch which can allocate which segment a particular station is on? I guess the RB4011iGS+RM ports can be isolated on different VLANs (so that the switch never sees the traffic), but then one needs to deal with the broadcast/multicast mess for IOT, etc. (or is there a simple solution)?
Thanks!
Seems that all firewall/NAT/routing is SW based with hw offload only for IPsec. The spec test results (https://mikrotik.com/product/rb4011igs_ ... estresults) indicate (based on packet size) 800k-5m pps with "routing none (fast path)", 800k-1m pps with "25 simple queries," and ~600k pps with "25 simple filter rules."
- What is no routing-fast path? Would most established masqueraded NAT fall into this? I am guessing not.
- What is a "simple query" vs. "simple filter rule"? Right now, I have 3 VLANs, 7 NAT rules and 15 filters, and use L2TP IpSec, so not sure where I'd expect to be on the spectrum.
- Our office is cutting the cord and moving to video streaming for TV, and all Wi-Fi calling for voice. Does anybody have a sense for the average packet size for NetFlix, Hulu, apple Wi-Fi calling?
Finally, the assuming the RB4011iGS+RM is the edge router, is there any advantage in plugging each of the 6 access points into the RB4011iGS+RM directly vs. all traffic going to a downstream switch which can allocate which segment a particular station is on? I guess the RB4011iGS+RM ports can be isolated on different VLANs (so that the switch never sees the traffic), but then one needs to deal with the broadcast/multicast mess for IOT, etc. (or is there a simple solution)?
Thanks!