MikroTikãSoftware-Baserã«ãŒã¿ãŒãçç£ããCPUããã©ãã£ãã¯åŠçã®å€§éšåãåŒãç¶ãããšã¯ç§å¯ã§ã¯ãããŸããã ãã®ã¢ãããŒãã«ã¯å©ç¹ããããŸãã ã»ãšãã©ãã¹ãŠã®æ©èœãããã°ã©ã ãããã¹ãŠã®ããã€ã¹ã«å¯ŸããŠæ¯èŒçåäžãªã·ã¹ãã ãç¶æã§ããŸãã ããããã¹ããŒãã§ã¯ãå°çšããããæèŒããã«ãŒã¿ãŒã«åžžã«é ãããšã£ãŠããŸãã
ãœãããŠã§ã¢ããã±ãŒãžã®åŠçã«ã¯ãããã€ãã®æ¬ ç¹ããããŸãã
- ã¯ã€ã€ã¹ããŒãã®äžè¶³-ããã»ããµïŒç¹ã«ã·ã³ã°ã«ã³ã¢ïŒã¯ãå°çšããããããé«éã«å®è¡ã§ããŸããã
- ããã¯ã éåžžã«å€§éã®ãã©ãã£ãã¯ïŒDoS / DDoSãªã©ïŒã§ã¯ãã³ã³ãœãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ããã§ãã«ãŒã¿ãŒã«æ¥ç¶ã§ããªãå ŽåããããŸãã ãã¹ãŠã®ããã»ããµæéããã©ãã£ãã¯åŠçã«ãã£ãŠå æãããŸãã
- ã¹ã±ãŒãªã³ã°ã®è€éãã ããŒããŠã§ã¢ã§ãã±ãããåŠçããé床ãäžããã¢ãžã¥ãŒã«ãè¿œå ããããšã¯ã§ããŸããã
éçºè ã¯ãç¶æ³ãæ¹åããããã«ããŸããŸãªããŒããŠã§ã¢ããã³ãœãããŠã§ã¢ãœãªã¥ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããŸãã
- äœã³ã¹ãã¢ãã«ã®ã¹ã€ãããããã«ãããCPUããã€ãã¹ããŠã¬ã€ã€2ãã©ãã£ãã¯ãåŠçã§ããŸãã
- åªãããããã¯ãŒã¯ããã ïŒCCRã©ã€ã³ïŒãåããSoCã
- ããŒããŠã§ã¢æå·åã䜿çšãã
- ããã±ãŒãžïŒFastPathããã³FastTrackïŒã®ãœãããŠã§ã¢åŠçã®æ°ãåæžããããŸããŸãªãã¯ãããžãŒã«ã€ããŠèª¬æããŸãã
SlowPathãšFastPath
SlowPathã¯ãå éšMikroTikãµãã·ã¹ãã ãéãåºæ¬çãªãã©ãã£ãã¯ãã¹ã§ããéåžžã«å€æ§ã§ããããã¹ãé·ãã»ã©ãCPUã®è² è·ãé«ããªããé床ãäœäžããŸãã
FastPath-ããªã倧ããªåŠçãŠãããããã€ãã¹ããŠãã©ãã£ãã¯ã転éã§ããã¢ã«ãŽãªãºã ã
äœæ¥ç°å¢ãšããã€ã¹ã®ãµããŒã
ææ°ã®MikroTikã«ãŒã¿ãŒããã³ããŒãã¯FastPathããµããŒãããŠããŸãããwikiã«è©³çŽ°ãªãªã¹ãããããŸãã
ã¢ãã« | ã€ãŒãµãããã€ã³ã¿ãŒãã§ã€ã¹ã®ãµããŒã |
---|---|
RB6xxã·ãªãŒãº | ãšãŒãã«1,2 |
RB7xxã·ãªãŒãºã®ã»ãšãã© | ãã¹ãŠã®ã€ãŒãµãããããŒã |
RB800 | ãšãŒãã«1,2 |
RB9xxã·ãªãŒãº | ãã¹ãŠã®ã€ãŒãµãããããŒã |
RB1000 | ãã¹ãŠã®ã€ãŒãµãããããŒã |
RB1100ã·ãªãŒãº | ether1-11 |
RB2011ã·ãªãŒãº | ãã¹ãŠã®ã€ãŒãµãããããŒã |
RB3011ã·ãªãŒãº | ãã¹ãŠã®ã€ãŒãµãããããŒã |
CRSã·ãªãŒãºã«ãŒã¿ãŒ | ãã¹ãŠã®ã€ãŒãµãããããŒã |
CCRã·ãªãŒãºã«ãŒã¿ãŒ | ãã¹ãŠã®ã€ãŒãµãããããŒã |
ãã®ä»ã®ããã€ã¹ | ãµããŒããããŠããŸãã |
ãŸããéã€ãŒãµãããã€ã³ã¿ãŒãã§ã€ã¹ã®åå¥ã®ãªã¹ãïŒ
ã€ã³ã¿ãŒãã§ãŒã¹ | FastpathãµããŒã | ã泚æ |
---|---|---|
ã¯ã€ã€ã¬ã¹ | ã¯ã | |
æ© | ã¯ã | 6.29ãã |
VLANãVRRP | ã¯ã | 6.30ãã |
ãã³ãã£ã³ã° | ã¯ã | 6.30ããå§ãŸãRXãã©ãã£ãã¯ã®ã¿ |
EoIPãGREãIPIP | ã¯ã | 6.33ããã ãã®ãªãã·ã§ã³ãæå¹ã«ãããšããã¹ãŠã®ãã³ãã«ãã©ãã£ãã¯ãFastPathãééããããã§ã¯ãããŸãã |
L2TPãPPPoE | ã¯ã | 6.35ãã |
MPLS | ã¯ã | çŸåšãMPLSé«éãã¹ã¯MPLS亀æãã©ãã£ãã¯ã«ã®ã¿é©çšãããŸãã MPLSã®å ¥åããã³åºåã¯ä»¥åãšåæ§ã«åäœããŸãã |
ãã®ä» | ãã |
FastPathã§ã¯ãåä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ãšéä¿¡ã€ã³ã¿ãŒãã§ã€ã¹ã®äž¡æ¹ãå®å šã«ãµããŒãããå¿ èŠããããŸãã ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ããŒããŠã§ã¢ãã¥ãŒã®ã¿ãæå¹ã«ããå¿ èŠããããŸãã
æåŸã«ãFastPathã¯æçåããããã©ãã£ãã¯ãæ¬åœã«å«ããŸãã ãã±ãããæçåãããŠããå ŽåãCPUã§ç¢ºå®ã«ã¹ã¿ãã¯ããŸãã
FastPathãšããªããž
ããªããžã¯ãè€æ°ã®ããŒããŠã§ã¢ïŒãŸãã¯ãœãããŠã§ã¢ïŒã€ã³ã¿ãŒãã§ã€ã¹éã®ã¬ã€ã€ãŒ2éä¿¡ãäœæããããã«äœ¿çšããããœãããŠã§ã¢ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã ã«ãŒã¿ãŒã®ããªããžã§4ã€ã®ã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹ïŒããã³hw=yes
ãæå¹åïŒãš1ã€ã®ã¯ã€ã€ã¬ã¹ãçµã¿åãããå Žåãã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹éã®ãã©ãã£ãã¯ã¯ãœãããŠã§ã¢ã€ã³ã¿ãŒãã§ãŒã¹ããã€ãã¹ããã€ãŒãµããããšã¯ã€ã€ã¬ã¹éã®ãã©ãã£ãã¯ã¯ãœãããŠã§ã¢ããªããžã䜿çšããŸãã è€æ°ã®ãããïŒããšãã°RB2011ïŒãåããã«ãŒã¿ãŒã§ã¯ãç°ãªããããããã®ã€ã³ã¿ãŒãã§ã€ã¹éã®ãã©ãã£ãã¯ã¯ãœãããŠã§ã¢ããªããžã®æ©èœã䜿çšããŸãïŒè² è·ã軜æžããããã«ãã€ã³ã¿ãŒãã§ã€ã¹ã¯åã«ãããã³ãŒããçµåããã ãã§æ©èœããŸãïŒã
FatsPath-CPUïŒãœãããŠã§ã¢ããªããžïŒãééãããã©ãã£ãã¯ã®ã¿ãæããŸããéåžžãç°ãªããããããã®ã€ã³ã¿ãŒãã§ã€ã¹éã®ãã©ãã£ãã¯ã§ãããã hw=yes
ãªãã·ã§ã³ãç¡å¹ã«ãªã£ãŠããŸãã
ãã±ãããããŒã§ã¯ãããªããžãééãããã©ãã£ãã¯ã¯æ¬¡ã®ãšããã§ãã
ããã«è©³çŽ°ïŒ
ããã¯ãããªããžèšå®ã«å«ãŸããŠããŸãïŒèšå®ã¯ãã¹ãŠã®ããªããžã€ã³ã¿ãŒãã§ã€ã¹ã§åãã§ãïŒ[ããªããž]-> [èšå®]-> [FastPathãèš±å¯]ã«ã¯ãã«ãŠã³ã¿ãŒã衚瀺ãããŸãã
Bridgeã§FastPathãæ©èœãããã«ã¯ã次ã®æ¡ä»¶ãæºããå¿ èŠããããŸãã
- ããªããžã€ã³ã¿ãŒãã§ã€ã¹ã«VLANèšå®ã¯ãããŸããïŒVLANãããŒããŠã§ã¢ã¬ãã«ã§èšå®ãããŠããCRSã·ãªãŒãºã«ã¯é¢ä¿ãªããšæããŸãããééã£ãŠããå¯èœæ§ããããŸãïŒ
-
/interface bridge filter
ããã³/interface bridge nat
ã«ã¯ã«ãŒã«ããããŸããããããã¯ããã¬ãŒã ãééãã2çªç®ã®åè·¯ããã®åããããã¯ã§ãã - IPãã¡ã€ã¢ãŠã©ãŒã«ãæå¹ã«ãªã£ãŠããŸããïŒ
use-ip-firwall=no
ïŒã ãã©ãã£ãã¯ããã£ããã£ããŠãããã¯ãŒã¯ããããã°ããããã®åªããæ©èœã§ãããç¶ç¶çã«æå¹ã«ããããšã¯ã»ãšãã©ãããŸããã - ã¡ãã·ã¥ãšã¡ã¿ã«ãŒã¿ãŒã䜿çšããªãã§ãã ãã
- ã€ã³ã¿ãŒãã§ã€ã¹ã§å®è¡ãããŠããŸããïŒã¹ããã¡ãŒãããŒãããã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒã
FastPathãšãã³ãã«
ç°¡åã«èšããšããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãäžéšã®ãã±ãããä»ã®ãã±ããã®è² è·éšåã«ã«ãã»ã«åããããšã§ãã PacketFlowã«æ²¿ã£ãŠé²ããšãå ã®ãã±ããã¯èµ€ãç·ã§ããŒã¯ãããå ã®ãã±ããã¯ãã³ãã«ãããã³ã«ãã±ããã«ã«ãã»ã«åãããŸãïŒããšãã°ãipipãŸãã¯gre; eoipã¯ããªããžã³ã°ã®æ±ºå®ãååŸïŒããã³ååŸïŒããŸã;ãã³ãã«ãã±ããã¯ããã«èå³æ·±ãã§ããã fastpathïŒã
FastPathã®ãã³ãã«ãã©ãã£ãã¯ã¯ããã¡ã€ã¢ãŠã©ãŒã«ããã¥ãŒããããã¹ããããVRFãIPã¢ã«ãŠã³ãã£ã³ã°ã§ã¯è¡šç€ºãããŸããã ãã ãããã±ããã®äžéšã¯åŒãç¶ãSlowPathãä»ããŠéä¿¡ãããŸããããã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæ§æããéã«èæ ®ããå¿ èŠããããŸãã
FastPathããã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã§æ©èœããã«ã¯ã次ã®æ¡ä»¶ãæºããããŠããå¿ èŠããããŸãã
- ipsecæå·åã䜿çšããªãã§ãã ãã
- ãã±ããã®æçåãåé¿ããïŒmtuãæ£ããæ§æããïŒ
- ãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã§
allow-fast-path=yes
ãæå¹ã«ããŸã
FastPathããã³Layer3
ã¬ã€ã€ãŒ3ã¯ãµããããéã§ã®ãã±ããã®éä¿¡ã§ãããã«ãŒã¿ãŒã¯ã«ãŒãã£ã³ã°ããŒãã«ãäœæããŠãã¯ã¹ããããã«è»¢éããŸãã
ãã±ãããããŒã§ã¯ããããã¯ãŒã¯å±€ééãã©ãã£ãã¯ã¯æ¬¡ã®ããã«ãªããŸãã
æ·±ãè¡ã
ãããŠããã«æ·±ã
FastPathãã¬ã€ã€ãŒ3ã§æ©èœããã«ã¯ã次ã®æ¡ä»¶ãæºããããŠããå¿ èŠããããŸãã
- ãã¡ã€ã¢ãŠã©ãŒã«ã«ã«ãŒã«ãè¿œå ããªãã§ãã ããïŒçµ¶å¯Ÿã«ãNATã§ãïŒã
- ã¢ãã¬ã¹äžèŠ§ã«ãšã³ããªãè¿œå ããªãã§ãã ããã
-
parent=global
Simple Queuesããã³Queues Treeãæ§æããããFastPathãæ©èœãããäºå®ã®ã€ã³ã¿ãŒãã§ãŒã¹ãæ§æãããããªãã§ãã ããã - ã¡ãã·ã¥ãšã¡ã¿ã«ãŒã¿ãŒã䜿çšããªãã§ãã ããã
- æ¥ç¶ãã©ãã«ãŒãç¡å¹ã«ããŸãã autoãªãã·ã§ã³ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ã«ãŒã«ããªãå Žåã«æ©èœããFastPathå°çšã«å°å ¥ãããŸããã
-
/ip accounting
䜿çšããªãã§ãã ããã -
/ip route vrf
ã¯äœ¿çšããªãã§ãã ããã -
/ip hotspot
æ§æããªãã§ãã ããã - ipsecããªã·ãŒãè¿œå ããªãã§ãã ããã
- ã«ãŒããã£ãã·ã¥ãæå¹ã«ããå¿ èŠããããŸãã
- ç©æ¥µçã«äœ¿çšããªãã§ãã ããïŒ
/tool mac-scan
ããã³/tool ip-scan
- ã¹ããã¡ãŒãããŒããããã³ãã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒãå®è¡ãããšãFastPathã«å¹²æžããŸãã
ããã¯ipèšå®ã«å«ãŸããŠããŸãïŒ[IP]-> [Settings]ã§ãæ£åžžã«åŠçããããã±ããã®ã«ãŠã³ã¿ãŒã確èªã§ããŸãã
ããŒã ã«ãŒã¿ãŒã®ã¹ã¯ãªãŒã³ã·ã§ããã ããªãè² è·ã®é«ããã¡ã€ã¢ãŠã©ãŒã«ããããããã€ãã®åžžææå¹ãªL2TP / IPSecæ¥ç¶ãšãã¥ãŒããããŸãã FastPathã倢èŠãããšããã§ããŸããã
Fasttrack
ãã±ãããããŒããã°ããééããããã®IPãã±ããã®ã©ããªã³ã°ãã¯ãããžãŒã
FastTrackãæ©èœããã«ã¯ã次ã®æ¡ä»¶ãé å®ããå¿ èŠããããŸãã
- ã«ãŒããã£ãã·ã¥ãšFastPathãæå¹ã«ããŠã¢ã¯ãã£ãã«ããå¿ èŠããããŸãã
- æ£ãããã©ãã£ãã¯ã©ããªã³ã°æ§æã
- UDPããã³TCPãã©ãã£ãã¯ã§ã®ã¿æ©èœããŸãã
- ã¡ãã·ã¥ãšã¡ã¿ã«ãŒã¿ãŒã䜿çšããªãã§ãã ããã
- ç©æ¥µçã«äœ¿çšããªãã§ãã ããïŒ
/tool mac-scan
ããã³/tool ip-scan
- ã¹ããã¡ãŒãããŒããããã³ãã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒãå®è¡ãããšãFastTrackã«å¹²æžããŸãã
fasttrackãšããŠããŒã¯ããããã©ãã£ãã¯ã¯ã以äžã§åŠçãããŸããã
- ãã¡ã€ã¢ãŠã©ãŒã«ãã£ã«ã¿ãŒïŒããã¯è°è«ã®äœå°ããããŸãããäŸã§çç±ã瀺ããŸãïŒã
- ãã¡ã€ã¢ãŠã©ãŒã«ãã³ã°ã«;
- IPsec
- parrent = globalã®ãã¥ãŒã
- ãããã¹ããã;
- VRF
fasttrackãééãããã±ããã«äœããå¹²æžãããšãäœéãã¹ã«æ²¿ã£ãŠæ®ãã®ãã¹ãŠã®ãã±ãããšåæ§ã«éä¿¡ãããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã«ã«ãŒã«ïŒä»¥äžãåç §ïŒãè¿œå ããããšã§æå¹ã«ãªããŸãã FastTrackã§ã¯ã確ç«ãããæ¥ç¶ããã®ãã±ããã®ã¿ãããŒã¯ãããŸãïŒæ°èŠãšããŠããŒã¯ã§ããŸãããNATã«åé¡ãçºçããŸãïŒã ãã£ã«ã¿ãŒããŒãã«ã䜿çšãããçç± äºåã«ãŒãã£ã³ã°ã§fasttrackãããŒã¯ãããšãåã³NATã«åé¡ãçºçããŸãã
æš¡æ¬è©Šéš
ãã¡ã¹ããã¹ | æ¥ç¶ãã©ãã«ãŒ | NAT | Fasttrack | ã¹ããŒã | CPU |
---|---|---|---|---|---|
- | - | - | - | ã932Mb /ç§ | 100ïŒ ïŒãããã¯ãŒã¯ãã€ãŒãµãããïŒ |
+ | - | - | - | ã923Mb /ç§ | 65-75ïŒ ïŒãããã¯ãŒãã³ã°ãã€ãŒãµããããæªåé¡ïŒ |
+ | + | - | - | ã680Mb /ç§ | 100ïŒ ïŒãããã¯ãŒã¯ããã¡ã€ã¢ãŠã©ãŒã«ãã€ãŒãµãããïŒ |
+ | + | + | - | ã393Mb /ç§ | 100ïŒ ïŒãããã¯ãŒã¯ããã¡ã€ã¢ãŠã©ãŒã«ãã€ãŒãµãããïŒ |
+ | + | + | + | ã911Mb /ç§ | 60-80ïŒ ïŒãããã¯ãŒãã³ã°ãã€ãŒãµããããæªåé¡ïŒ |
ãããŠïŒæåŸã®ãã¹ãã®ããã«ïŒäœãèšå®ãããã©ã®ããã«æ©èœãããïŒ
ãã£ã«ã¿ãªã³ã°ã«ãŒã«ã¯åŒãç¶ããã©ãã£ãã¯ãåŠçãïŒç¢ºç«ãããé¢é£ãã©ãã£ãã¯ã®èš±å¯ãç¡å¹ã«ãããšãé¢é£ãããã©ãã£ãã¯ã¯ãããããããŸãïŒãFastTrackã«å°éããªãã£ããã±ããã¯ãã¹ãã«ãŒãã£ã³ã°+ãã³ã°ã«ã§ãã£ãããããŸããã
æ¥ç¶ãã©ãã«ãŒã§ã¯ãåãååã®ãã©ã°ã§FastTrackæ¥ç¶ã远跡ã§ããŸãã
[IP]-> [èšå®]ã«ãŠã³ã¿ãŒã§ãFastTrackãã¢ã¯ãã£ãã§åäœããŠããããFastPathãåäœããŠããªãããšãããããŸãã
/ip firewall filter add action=fasttrack-connection chain=forward connection-state=established,related add action=accept chain=forward connection-state=established,related add action=accept chain=forward connection-state=new add action=drop chain=forward /ip firewall mangle add action=mark-packet chain=postrouting connection-state=established,related new-packet-mark=q1 passthrough=no src-address=20.20.20.0/24 /ip firewall nat add action=masquerade chain=srcnat out-interface=ether1
çµè«ã®ä»£ããã«
䜿çšãããã©ãã
- FastPath for Bridge-ééããªãã¯ãã å°ãªããšãCPUã®è² è·ãæžãããŸãã
- ãã³ãã«ã®FastPath-ãããã æå·åãããŠããå Žåã¯æ©èœããããªãã«ãªããŸãã
- ã¬ã€ã€ãŒ3ã®FastPath-è«äºã®çã«ãã«ãŒã¿ãŒã®æ©èœã®ã»ãšãã©ã倱ãããŸãã éçã®ã€ã³ã¿ãŒãããããééããã倧èŠæš¡ãªãããã¯ãŒã¯ã§ã¯ããããã¯ãŒã¯ãç¬èªã®ïŒå°ããªïŒè³éãç²åŸã§ããŸãã
- MPLS / VLAN /ãã³ãã£ã³ã°/ VRRPã®FastPath-å¯èœã§ããã°ãèªåçã«æå¹ã«ããŸãã å¶åŸ¡ã®ããã®åå¥ã®ãªãã·ã§ã³ã¯ãããŸããã
- FastTrack-ãã¥ãŒããã³åå·çãªãã¡ã€ã¢ãŠã©ãŒã«ã®ãªãããŒã ããã³SOHOæ§æã«é©ããŠããŸãã 1ã€ã®ã¯ã©ã€ã¢ã³ãã§ã®ç·åçãªãã¹ãã¯é©åã«èŠããŸãããå®éã«ã¯ãFastTrackãééããŠãªãŒã¯ãããã©ãã£ãã¯ã泚ææ·±ãç£èŠããåå ãæ¢ãå¿ èŠããããŸãã
ãã®ä»ã®ãªã³ã¯
https://wiki.mikrotik.com/wiki/Manual:Fast_Path
https://wiki.mikrotik.com/wiki/Manual:IP/Fasttrack
http://mum.mikrotik.com/presentations/UA15/presentation_3077_1449654925.pdf