this post was submitted on 29 Nov 2023
1 points (100.0% liked)
Homelab
371 readers
3 users here now
Rules
- Be Civil.
- Post about your homelab, discussion of your homelab, questions you may have, or general discussion about transition your skill from the homelab to the workplace.
- No memes or potato images.
- We love detailed homelab builds, especially network diagrams!
- Report any posts that you feel should be brought to our attention.
- Please no shitposting or blogspam.
- No Referral Linking.
- Keep piracy discussion off of this community
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Mikrotik does support l3 offloading to the switch chip on some switch models assuming you are running version 7 of their OS, ideally latest has most of the bugs ironed out around l3hw from my experience. CRS317 is one of those switches that do support l3 hw offload. My experience is it handles line rate l3 routing but I am also using it as a very simple L3 router, no NAT etc. You have to be cautious of which models you use with which feature set.
I would give this doc a read over to see if all of your requirements can be met: https://help.mikrotik.com/docs/display/ROS/L3+Hardware+Offloading according to it, CRS317 does support NAT in hardware but I personally haven't tried. I use a CCR2116 with L3 offload for any firewall rules that are more than basic as well as NAT, it works great from my experience.
The only shortcomming I have with mikrotik l3 offload right now is ipv6 support, they do support it but the lack of a fastrack action for ipv6 firewall rules means you have to offload all ipv6 traffic (no statefull firewall just switch acl's) or offload none of it.