Feature missing from Winbox in v6.12, you can use console for now, Switch menu will be in Winbox from v6.13How is the switch chip configured without a switch menu option?
Hi Normis, thank you for your comment! I understand this of course and it was only connected to Ether8 for the photo. After that I made lots of different combinations (routed, NAT, bridged, etc.) as you can see in my screenshots and test results.Quick note to Quindor, you are connecting to Ether8, but the IP address is on Ether1. Unlike the RB2011, the CCR series doesn't have all ports switched, so you need to connect to Eth1 and configure the device according to your needs.
I would like to know this too.Hijacking a little - normis can you confirm/deny if dual PSU will make its way to 1036 models?
It would be a different device then. As you can see, all new CCR units have dual PSU, so if we release a new 36 core model, it will have them. We are working on it.I would like to know this too.Hijacking a little - normis can you confirm/deny if dual PSU will make its way to 1036 models?
Ok, cool. I hoped a bigger interconnect then 1Gbps would have been used, but I can understand that restraint from a cost perspective.All switched ports share 1gbps full duplex link to CPU, other than that there should be no difference
wery sad- How much noise does it make?
Sadly Mikrotik does not use PWM fans yet which have caused less noise, then again, this is a datacenter product and for in a datacenter the CCR is in no way loud or obtrusive.
I would not advise you putting it in your living room or something, but a few meters away or inside of a closet (provide ventilation) it should not be intrusive during normal usage.
I have checked and while I am able to set the fan to manual mode or auto mode, it seems to only specify which kind of fan is connected (2 wire or 3 wire) and not give me any control over it.@Quindor Is it possible to set the fans so that they spin at a constant rate (eg. 30% or 50%) regardless of CPU load ?
To answer another question from @KoDAk there does not seem to be a manual speed control option and replacing the cooling will be quite hard since the case is 1U so any kind of cooling will be a heatsink with forced airflow which results in 40mm fans.[admin@MikroTik] /system health> print
fan-mode: auto
use-fan: main
active-fan: none
cpu-overtemp-check: yes
cpu-overtemp-threshold: 100C
cpu-overtemp-startup-delay: 1m
voltage: 23.8V
current: 627mA
fan-speed: 0RPM
temperature: 23C
cpu-temperature: 45C
power-consumption: 14.9W
What a shame...Another thing I just realized. There is no active monitoring on the PSU's. The routerboard does not know how many PSU's are actually connected (photo's only show power cables going from the PSU module to the mainboard) so there is no way to check if 1 or 2 power cables are connected and/or working.
the CCR1009 has the power to run a medium sized ISP, so, I don't agree to the above.at max it is small office and Home-office (where noise is big problem
Good question.What a shame...Another thing I just realized. There is no active monitoring on the PSU's. The routerboard does not know how many PSU's are actually connected (photo's only show power cables going from the PSU module to the mainboard) so there is no way to check if 1 or 2 power cables are connected and/or working.
There is a LED indication of PSU status?
How do I know if one of the PSUs broken?
if swapped FANs are of good quality and does not damage fan controller you are fine. So, when choosing FANs check if power usage of new ones is in the same ballpark as ones supplied from us. Also note that different fans can report RPM and starting voltage can be different so reading in RouterOS can be different from reality after the swap.I think your best bet would be replacing both fans with Noctua's. I use Noctua in all my equipment that needs to be (virtually) silent. Not cheap, but the best fans on the market. The Noctua NF-A4x10 FLX seems to have the right dimensions and uses the same 3pin connector. I have no idea about air rate and flow though and if they will actually keep the CCR cool enough, etc. And while I think these are your best bet in silencing your CCR, your warranty will absolutely be voided.
OK i mean:the CCR1009 has the power to run a medium sized ISP, so, I don't agree to the above.at max it is small office and Home-office (where noise is big problem
Ok, I understand, but I don't think this is the right topic to discuss such a thing. The CCR1009 is a perfect device suited for a lot of tasks as it is right now. But it certainly isn't a "one size fits all" device, which is impossible anyway in my opinion.OK i mean:the CCR1009 has the power to run a medium sized ISP, so, I don't agree to the above.at max it is small office and Home-office (where noise is big problem
I dream to see model like:
*RB2011UiAS-2HnD-IN* but on CPU: TLR4-00980CG-10CE
(sfp \ 1g Ethernet ports 10-12 (PoE on 2 ports of them) \ usb \802.11b/g/n \ LCD )
and price 250-350$
and CRS mast have only CPU: TLR4-00980CG-10CE and more
Thnx's! I always value other people sharing information about new products so when I get a first, I'm happy to oblige! Karma is always appreciated.@Quindor, thank you again for the detailed reply regarding the fan settings.
Any chance you have the specs of the fans ? Mainly Voltage and Amp (eg. 12VDC, 0.11A). I'm thinking of replacing them with quality fans either from Delta, Sanyo-Denki or NMB.
Also, from the pictures, the fans look like they are 40x40x20mm. I believe Noctua only has 40x40x10mm so the 10mm gap could be an issue.
Best regards.
An LED indication at the very least would be useful. I mean you don't imagine you're going to have 2 PSU's fail straight away and it's useful to be able to connect the router up to independant power rails (and PoE which is cool), but some sort of monitoring integration would be excellent in any future revisions of the 1036 and 1072's *hint hint*Good question.What a shame...Another thing I just realized. There is no active monitoring on the PSU's. The routerboard does not know how many PSU's are actually connected (photo's only show power cables going from the PSU module to the mainboard) so there is no way to check if 1 or 2 power cables are connected and/or working.
There is a LED indication of PSU status?
How do I know if one of the PSUs broken?
In my opinion such a device should have LEDs which are indicating the status of each PSU. Additionally this information should also be available via SNMP. The latter is especially important for ISPs. I don't visit all of our sites on a daily basis to check LEDs.
What about inter-vlan routing on the 10g port?+1 thank you for this excellent overview. Much appreciated. So then, it does not route over 1 gigabit over a single upstream port? What is the 10 gigabit SFP+ port for then?
starting from RouterOS 6.13 PSU monitoring will be possible. Due to some technical difficulties this feature was delayed. Same will be true for CCR1016-12S-1S+- Can the dual PSU be monitored?
No, the PSU module is only connected using power connectors to the mainboard. The routerboard monitors the voltage that it is receiving, but it cannot determine or monitor if 1, 2 or 3 power sources are connected. In theory the power source with the highest voltage will be used first and fail-over will happen automatically if that source fails.
I think I might have explained it wrongly then. I believe it certainly can achieve much more speed then 1Gbit.+1 thank you for this excellent overview. Much appreciated. So then, it does not route over 1 gigabit over a single upstream port? What is the 10 gigabit SFP+ port for then?
(sorry I have not updated myself since the Routerboard 450g series)
Sadly I have no 10Gbit equipment so I am unable to test that at this time. I do believe they have fixed some inter-vlan routing issues over a single port since one of the latest versions of RouterOS so it should be okay?What about inter-vlan routing on the 10g port?
That would be awesome! I guess it's able to monitor all the voltages separately and thus determine how many PSU's are connected. Would be awesome! When the feature arrives I will test it and then change my information post!starting from RouterOS 6.13 PSU monitoring will be possible. Due to some technical difficulties this feature was delayed. Same will be true for CCR1016-12S-1S+
None is available yet but it isn't too hard to puzzle together.can come one post
architecture diagram of 1009?
SFP port seems to be part of the switch group according to the wiki :None is available yet but it isn't too hard to puzzle together.can come one post
architecture diagram of 1009?
SFP port : Direct CPU
SFP+ port : Direct CPU
Port 1-4: Switch with 1Gbps CPU uplink to CPU (Basically a 5 port switch chip with one port internally connected)
Port 5-8: Direct CPU
Did you need to know anything else? Looking at other CCR block diagram's and how the TileGX CPU is built and what kind of buses it has can also be helpful!
According to Baltic Networks, shipment is expected to arrive within these couple of days.What is the US availability date, I see it available for pre-order only?
We already received our unit from one of the US resellers (roc-noc.com). They are now sold out of the CCR1009-8G-1S-1S+model, but do have some of the CCR1009-8G-1S-1S.What is the US availability date, I see it available for pre-order only?
I hoped both sfp ports are directly connected to the cpu. The Tile should support this.SFP port seems to be part of the switch group according to the wiki :None is available yet but it isn't too hard to puzzle together.can come one post
architecture diagram of 1009?
SFP port : Direct CPU
SFP+ port : Direct CPU
Port 1-4: Switch with 1Gbps CPU uplink to CPU (Basically a 5 port switch chip with one port internally connected)
Port 5-8: Direct CPU
Did you need to know anything else? Looking at other CCR block diagram's and how the TileGX CPU is built and what kind of buses it has can also be helpful!
http://wiki.mikrotik.com/wiki/Switch_Chip_Features
- PRTGHow do I know if one of the PSUs broken?
A little or small ventilated 19" Rack is in my eyes the best solution for becomingat max it is small office and Home-office (where noise is big problem
I didn´t consider, if I own a router such as the CCR1009-8G-1S-1S+ then*RB2011UiAS-2HnD-IN* but on CPU: TLR4-00980CG-10CE
I am considering with you but the LED light should be more made for home usageIn my opinion such a device should have LEDs which are indicating the status of each PSU.
# RB2011 backup config /ip firewall filter add chain=input comment="default configuration" protocol=icmp add chain=input comment="default configuration" connection-state=established add chain=input comment="default configuration" connection-state=related add action=drop chain=input comment="default configuration" in-interface=ether1-gateway # RB2011 quickset config /ip firewall filter add chain=input action=accept protocol=icmp comment="default configuration" add chain=input action=accept connection-state=established comment="default configuration" add chain=input action=accept connection-state=related comment="default configuration" add chain=input action=drop in-interface=ether1-gateway comment="default configuration" add chain=forward action=accept connection-state=established comment="default configuration" add chain=forward action=accept connection-state=related comment="default configuration" add chain=forward action=drop connection-state=invalid comment="default configuration" # http://wiki.mikrotik.com/wiki/Manual:IP/Firewall/Filter /ip firewall filter add chain=input connection-state=invalid action=drop comment="Drop Invalid connections" add chain=input connection-state=established action=accept comment="Allow Established connections" add chain=input protocol=icmp action=accept comment="Allow ICMP" add chain=input src-address=192.168.1.0/24 action=accept in-interface=!ether5-wan add chain=input action=drop comment="Drop everything else" add chain=forward protocol=tcp connection-state=invalid action=drop comment="drop invalid connections" add chain=forward connection-state=established action=accept comment="allow already established connections" add chain=forward connection-state=related action=accept comment="allow related connections" # http://forum.mikrotik.com/viewtopic.php?f=13&t=74024 /ip firewall filter add action=drop chain=input comment="Drop invalid connections" connection-state=invalid add chain=input comment="Accept established connections" connection-state=established add chain=input comment="Accept related connections" connection-state=related add chain=input comment="Allow access from local network" in-interface=br-PrivateNetwork src-address=192.168.25.0/24 add chain=input comment="Allow access from guest network for DNS" dst-port=53 in-interface=br-GuestNetwork protocol=udp src-address=192.168.125.0/24 add action=log chain=input comment="Log everything else" disabled=yes log-prefix="IPv4 Drop input RR:" add action=drop chain=input comment="Drop everything else" add action=drop chain=forward comment="Drop invalid connections" connection-state=invalid add chain=forward comment="Accept established connections" connection-state=established add chain=forward comment="Accept related connections" connection-state=related add chain=forward comment="Allow traffic from Local network" in-interface=br-PrivateNetwork src-address=192.168.25.0/24 add chain=forward comment="Allow Guest network going outside" in-interface=br-GuestNetwork out-interface=pppoe-***** src-address=192.168.125.0/24 add action=log chain=forward comment="Log everything else" disabled=yes log-prefix="IPv4 Drop forward RR:" add action=drop chain=forward comment="Drop everything else" # http://wiki.mikrotik.com/wiki/A_script_ ... ou_started /ip firewall filter add action=accept chain=input comment="Local access to RB for Winbox" disabled=no dst-port=8291 protocol=tcp src-address-list=local add action=jump chain=input comment="Treat all traffic equally" disabled=no jump-target=inbound add action=jump chain=forward comment="Treat all traffic equally" disabled=no jump-target=inbound add action=drop chain=inbound comment="Drop invalid" connection-state=invalid disabled=no add action=accept chain=inbound comment="Allow limited icmp" disabled=no limit=50/5s,2 protocol=icmp add action=drop chain=inbound comment="Drop excess icmp" disabled=no protocol=icmp add action=accept chain=inbound comment="Accept established" connection-state=established disabled=no add action=accept chain=inbound comment="Accept related" connection-state=related disabled=no add action=accept chain=inbound comment="Internal traffic can do what it wants." disabled=no src-address-list=local add action=drop chain=inbound comment="And drop everything else" disabled=no add action=accept chain=output comment="Allow everything out" disabled=noWhat would a reasonable set of rules look like?
/interface set ether5,ether6 disabled=yes failure: master-port and bandwidth settings not supported on this portWhat ethernet (non-SFP) ports should be used for LAN and for WAN links?
I have CCR1009 since 2 weeks but I remember from a mistake I disabled Ether1. and I connected in Ether2 without any problem. So you can configure from any port you wantQuick note to Quindor, you are connecting to Ether8, but the IP address is on Ether1. Unlike the RB2011, the CCR series doesn't have all ports switched, so you need to connect to Eth1 and configure the device according to your needs.
Hi mmigoro , MTK have noted that certain SFP+ routers are backwards compatible with SFP but requires it to be hard set on both sides to 1GB iirc.Does anybody know if SFP+ port supports also SFP modules (1,25gbps).
I would like to replace actual config (RB1100AHx2 + 2 gigabit media converters) with 1 CCR1009-8G-1S-1S+ and 2 SFP modules.
You are paying for the link right? Just ask them to set it to the specified settings and they should?Thanks for info.
I only have access to my side of the link, the other ends are at provider PoP's. So I guess I'm stuck with 1100AHx2...
If you're currently using 1100AHx2 with fiber-to-copper media converter, why not use that with the CCR1009 too ?I only have access to my side of the link, the other ends are at provider PoP's. So I guess I'm stuck with 1100AHx2...
Perhaps this answer from @janisk will matching best this question.Does anybody know if SFP+ port supports also SFP modules (1,25gbps).
I would like to replace actual config (RB1100AHx2 + 2 gigabit media converters) with 1 CCR1009-8G-1S-1S+ and 2 SFP modules.
Monitoring of PSU has already been implemented?starting from RouterOS 6.13 PSU monitoring will be possible. Due to some technical difficulties this feature was delayed. Same will be true for CCR1016-12S-1S+
/system healt print
fan-mode: auto
use-fan: main
active-fan: main
cpu-overtemp-check: yes
cpu-overtemp-threshold: 100C
cpu-overtemp-startup-delay: 1m
voltage: 23.7V
current: 763mA
fan-speed: 5081RPM
temperature: 36C
cpu-temperature: 54C
power-consumption: 18.1W
psu1-state: ok
psu2-state: ok
Have you tried to upgrade the CCR1009 to the newest version and see what that does?I just got my first Mikrotik (CCR1009-8G-1S-1S+). Have some previous experience with a cheaper device.
First issue, the Quicket menu via WebFig doesn't show any settings, all fields are empty. When I login via winbox, the quickset shows me the current configuration.
Second issue, the quickset menu in WebFig is showing Wireless settings although the wireless package is disabled.
Yes I believe that is correct! Nice drawing too, but, euhm, Mikrotik released their block diagram a while ago : http://i.mt.lv/routerboard/files/CCR100 ... 151432.pdf maybe you missed it.Is this how the architecture looks?
Combining the various datasheets this is what I have come up with.
MT could you please confirm?
Hi all,Related to the fans inside I found this one here, perhaps you would take a short overview
if this can be interesting for you. Noiseblocker BlackSilent Pro Fan PM2
Thanks for sharing this! i ordered two of them. Did they fit perfectly or do you have to made some changes to the case?Hi all,Related to the fans inside I found this one here, perhaps you would take a short overview
if this can be interesting for you. Noiseblocker BlackSilent Pro Fan PM2
I justed registered to let you know, that I've installed these fans today. They seem to work perfectly - I don't see any differences in temperature and I don't hear a thing
Thanks for all the information you guys provided in this thread, helped a lot!
They fit perfectly. No changes to the case or fans necessary. The package contains a gasket for vibration-free mounting - I didn't try to install them.Thanks for sharing this! i ordered two of them. Did they fit perfectly or do you have to made some changes to the case?
Do you have Mangle rules? Queues? What are you firewall rules?Hi, can I ask - I have CCR1009 as edge router with NAT.
I used Eth5 as WAN and Eth6 as LAN. But in high data load from customers - above 300Mbps, occurs high cpu usage of CCR up to 100% and traffic decerase to forexample 110Mbps and latency to internet is 100ms and higher. This is during 3-6s, then CPU goues back to 20%. And for a minute -two that repeats. Is my device bad or that config is wrong?
Thanks.
Simple Q cca 30x, firewall cca 70x, NaT 240xDo you have Mangle rules? Queues? What are you firewall rules?Hi, can I ask - I have CCR1009 as edge router with NAT.
I used Eth5 as WAN and Eth6 as LAN. But in high data load from customers - above 300Mbps, occurs high cpu usage of CCR up to 100% and traffic decerase to forexample 110Mbps and latency to internet is 100ms and higher. This is during 3-6s, then CPU goues back to 20%. And for a minute -two that repeats. Is my device bad or that config is wrong?
Thanks.
Could be as simple as the order of your rules.Simple Q cca 30x, firewall cca 70x, NaT 240x
Post your filter and mangle, when we can see what could be causing it.Previous PC router goes permanently on 70% on CPU load (dual-core 2200MHz Pentium. And it has lower latency to internet and no such issue, during 4 years.
I agree 100% with Normis, these products are ISP grade products.the CCR1009 has the power to run a medium sized ISP, so, I don't agree to the above.at max it is small office and Home-office (where noise is big problem
My main office is 500/500 fiber, feeding three bunch offices each with 100/100 fiber. Each office has a CCR1009 with 2GB. They have no issue sustaining 95~100mbps throughput, saturating the branch fiber. The main office routinely sustains 300mbps out to the offices.I am not sure they are small business grade in the VPN area, with users frequently referring to slower performance compared to RB1100AH.
With what VPN configuration?My main office is 500/500 fiber, feeding three bunch offices each with 100/100 fiber. Each office has a CCR1009 with 2GB. They have no issue sustaining 95~100mbps throughput, saturating the branch fiber. The main office routinely sustains 300mbps out to the offices.I am not sure they are small business grade in the VPN area, with users frequently referring to slower performance compared to RB1100AH.
Well they are saying that it can handle a "lot more than 500Mbps" with the correct VPN config:I am not sure they are small business grade in the VPN area, with users frequently referring to slower performance compared to RB1100AH.
MikroTik can confirm or deny this, but I believe the CCRs use the same IPSEC hardware chip which means the CCR1009 performance ought to be close to the other CCRs.Well they are saying that it can handle a "lot more than 500Mbps" with the correct VPN config:I am not sure they are small business grade in the VPN area, with users frequently referring to slower performance compared to RB1100AH.
http://forum.mikrotik.com/viewtopic.php?f=3&t=87892
according ezchip website the MiCA™ acceleration engines responsible for crypto acceleration have the following theoretical performance:MikroTik can confirm or deny this, but I believe the CCRs use the same IPSEC hardware chip which means the CCR1009 performance ought to be close to the other CCRs.Well they are saying that it can handle a "lot more than 500Mbps" with the correct VPN config:I am not sure they are small business grade in the VPN area, with users frequently referring to slower performance compared to RB1100AH.
http://forum.mikrotik.com/viewtopic.php?f=3&t=87892
We were able to get a max of 7.5 Gbps of encrypted throughput using EoIP over IPSEC in our testing of the CCR1036s.
http://www.stubarea51.net/2015/10/16/10 ... ip-tunnel/
Very helpful info! I've looked several times but never saw which chip was being used for IPSEC offload on the CCR. Just out of curiosity, where did you find the info on what chip is in the CCRs?according ezchip website the MiCA™ acceleration engines responsible for crypto acceleration have the following theoretical performance:
tilegx9 (ccr1009) 10Gbps of crypto and 5Gbps of compression
tilegx16 (ccr1016) 20Gbps of crypto and 10Gbps of compression
tilegx36 (ccr1036) 40Gbps of crypto and 20Gbps of compression
tilegx72 (ccr1072) 40Gbps of crypto and 20Gbps of compression
off course we have to take in count cpu and memory performance and the complexity of configuration
this are the chip manufacturer linksVery helpful info! I've looked several times but never saw which chip was being used for IPSEC offload on the CCR. Just out of curiosity, where did you find the info on what chip is in the CCRs?according ezchip website the MiCA™ acceleration engines responsible for crypto acceleration have the following theoretical performance:
tilegx9 (ccr1009) 10Gbps of crypto and 5Gbps of compression
tilegx16 (ccr1016) 20Gbps of crypto and 10Gbps of compression
tilegx36 (ccr1036) 40Gbps of crypto and 20Gbps of compression
tilegx72 (ccr1072) 40Gbps of crypto and 20Gbps of compression
off course we have to take in count cpu and memory performance and the complexity of configuration
Funny story, since purchasing the CCR1009 I've only used it as a testing router and temporary router where I needed it. Today I ported my configuration from the RB2011 I was using to my CCR1009 and am using it as my home "production" router!
I did set the CPU down to 600Mhz which has made it so that the stock fans just turn off. Performance is still miles and leagues ahead of the RB2011.
The reason for the switching the routers? I've started using a PPTP VPN tunnel to redirect some traffic to another site and anything more then 40Mbit would cause the RB2011 CPU to hit max CPU load and it became noticeable with other stuff I was running through it. With the CCR1009, even using 600Mhz, no problems whatsoever and I've seen it hit 60MBit to 80Mbit without problem!
Awesome device!
See for yourself. This was downloading about 16GB of data, I saw peaks up to 110Mbit but average was more around 60MBit. I have included a bandwith graph and 2 CPU graphs. One is of each CPU individually, one of them averaged together.what cpu usage when hitting 80mbit of pptp?? in tool profile you see cores evenly charged??