A PCIe network interface card that adds full router capabilities to your servers
mikrotik.com
mikrotik.com
the reason you would slap a router card in your rackmount server is because its an IOMMU passthrough to a k8s service load balancer or straight up just openstack and the push toward hyperconvergence. the switch is already virtual inside the kvm on openvswitch (has been for a decade now), but the router is still hardware and this product aims to solve that problem.
And it doesn't have cloud dependencies to manage it.
The bandwidth on the interfaces isn't high enough to match most enterprise customers needs -- 25GBe/40GBe had pretty marginal market penetration compared to 10G where you don't need hyperconverged solutions, and beyond that most major hyperscalers and others have skipped straight to 100G as far as I can see, to leverage economies of scale. And the CPU complex and ASIC together aren't powerful enough with enough resources to offload serious "service provider compute" workloads to; they even note specifically things like it reaches "line rate with Jumbo Frames", where most of those other solutions aim for line rate @ MTU, so I'm suspicious of that wording. And on top of that you need some actual dedicated engineering (operations, engineers) to utilize a solution like this versus just reserving AWS instances with ENA adapters or whatever. Anything this can do, something like Bluefield will just do better in every way, if you need the hardware yourself.
So I legitimately have a hard time envisioning anyone other than random nerds buying these. Any large customer is probably better off just going with Nvidia (Bluefield) or Intel (Mount Evans). But hey, for two 25GBe ports at the price of a normal 10GBe card, as long as I can pass them through directly I suppose I can handle RouterOS or whatever, and if the software gets more advanced that's cool too. And if it gets more people on the whole converged infrastructure bandwagon, sounds good!
I don't see this card being that popular in that market however; if you want solid tcp offload and asic acceleration there's xilinx cards with a good reputation already.
My hope (once I can actually get my hands on one) is this can integrate well for us by offloading a lot of the routing and NAT type functions for a managed service network offering software based box we sell that handles all of the "smart" network functions at the site + acts as the egress point.
I agree with you on most points though - and finding good people who know how to even use RouterOS seems like it would be a pain for companies as well.
1. people running weird janky WISPs, like, two guys and a pickup truck in some very rural parts of the USA. usually very budget limited.
2. small very budget limited ISPs in the developing world.
everyone else in the service provider is not using a $200 mikrotik to do serious routing of >10Gbps of traffic.
I may have been involved with those guys at some point…
I would be interested to hear more.
There are some imperfections, mostly related to bonding+ospf and vrrp-grouping but if one does not mind some warnings and a little scripts, one can make things work nicely.
Let's just say that BGP-signaled redundant uplinks and routing as close to the customer as possible are to strive for, instead of starting with a L2 port-isolation-pyramid nightmare.
It's definitely got home networks as a target market. It's one of the suggested use cases.
https://www.servethehome.com/mikrotik-ccr2004-1g-2xs-pcie-is...
Please check out this Kamuee software router and it has the performance of 100 Gbps without using SmartNIC based open soure Quagga/FRR open source routing suite although it's proprietary technology by NTT [2]. Perhaps it's not coincident that the original Zebra open source routing suite pre-cursor to the Quagga/FRR is also written by a Japanese.
Another related and promising software router technology from the startup Netris using SmartNIC [3],[4]. It aspires to provide automatic network operations platform that turns the physical network into a service like a cloud.
[1] Welcome to the Intel Ice Lake D Era with the Xeon D-2700 and D-1700 series:
https://news.ycombinator.com/item?id=30568011
[2] 100 GbE High Speed Software PC Router "Kamuee":
https://www.ntt.com/en/lp/router/Kamuee.html
[3] SmartNIC Linux router for modern data center:
https://www.netris.ai/how-to-select-a-network-gateway-for-yo...
[4] SmartNIC Linux router for modern data center (HN discussions):
I was cheating.
This has been done before with the likes of DSL modems that weren't actually modems but just router-on-a-card that would just have a Realtek PCI chip on the bus side, which then directly had its GMII interface hooked up to a conexant DSL modem/router package which itself then connected to the actual on-board modem.
The ports on another NIC would be assigned directly to the host. While I'm sure you can theoretically redirect them to this router wit a combination of VLANs and other Linux networking magic, you will be limited by your CPU and it's unlikely you'll manage more than a few Gbps.
Keep in mind that most routers are just computers too. Sometimes they are low-power computers with special hardware components to offload specific tasks so you can trade power for specialisation (which also comes with a rigidity trade-off, you can't change the hardware after the fact like for new protocols).
I've seen some option ROMs take 10 seconds or more depending on the card - hardware RAID controllers being a well known example.
it helps to keep costs down if you don't have any NRE.
Where I can see this being super cool though is niche use cases like highly portable servers and whatnot for things like VFX shoots. I once was contracted to built a set of highly mobile and durable servers for mobile rendering of 8K footage. I built the servers into some super durable hard case boxes that are usually used for shipping things like expensive camera equipment, military hardware, etc. The cases even have a valve to equalize pressure in case they get pushed deep underwater (like in the event of a boat capsizing) and a very robust waterproof gasket. Of course for the servers to be running the case must be open (mainly for cooling) but it would have been interesting to network multiple of them together AND other equipment without needing a separate physical device for routing. It would also have made scaling the system much easier if each server could also act as a router - you could bring one or 10 and each could function independently of each other.
[0]: https://www.washingtonpost.com/technology/2021/06/07/amazon-...
Do you want a cheap dual-port NIC at 25Gbps? How about we add some solid router capabilities on it for no extra price?
It uses another CPU to do that. GPU is fundamentally different, high memory bandwidth, embarrassingly parallel, virtually no branches, and what not. That's just using a different CPU to do more CPU, and using the same OS the host already runs.
Then it requires its own security maintenance (+training) and patches.
IOW the customer has full control of the host, but the cloud provider manages the smartnic. Incidentally, this is exactly what AWS does with their ENA adapters designed by... (ex-?)Anapurna Lab they bought some years ago (:
Pretty much all modern NICs are already using separate hardware to reduce the load on the main CPU. I.e. using a different CPU to do more CPU.
Without that you're looking at sacrificing a whole core or two just to handle 1Gbps, nevermind 10+.
To me, this suggests that it's packet-rate limited, and if so, it can really only be counted on to do 1500/9000 or ~16.6Gb/s with standard frames.
Consider a cloud provider who offers virtual machines to users: the physical host machine typically is involved in whatever networking path is necessary (e.g. an SDN), as well as the control plane software for managing VMs, and other tidbits. Moving the entire networking and SDN layer off the host system and onto an accelerator card, with your own customizations to the data path, means you can take those host resources and use them for VMs instead -- effectively increasing the total amount of capacity you have available. It's not just CPU time either: things like this also effectively increase available PCIe bandwidth, memory bandwidth, etc, available to users, by moving the resources the operator needs elsewhere.
There are some other benefits too, like you can run the whole security framework on a card like this. Or QoS controls. You could for example rent out the entire bare metal server to someone more or less and use a device like this to implement throttling/QoS/SDN transparently.
Most of the vendors are calling these "Data Processing Units" or "Infrastructure Processing Units" or whatever, but the idea is all the same. Offloading the networking/data paths into accelerators allows you to offer more raw compute to your users. For example, Nvidia Bluefield or Intel's new Mount Evans IPU.
This Mikrotik is basically the bargain-bin version of those products. Which is actually pretty cool. I could actually use a couple of 25GbE breakouts for that price...
It’s not for the enterprise but I’ll get some for home.
The way things are laid out in a hierarchy in a full system "/export" from a Mikrotik is so weird and annoying compared to a hierarchical junos configuration from a "show configuration" on a juniper router.
If people want to make a real router of an x86-64 system rather than putting a mikrotik pci-e card into it (wtf, why?) I'd recommend they go with vyatta or VyOS instead, or install something like a barebones centos or debian and then add FRR to it.
One thing I've been looking for is a hardware box that can replicate what Ubiquiti's EdgeRouter Infinity does: a handful of 10Gbps SFP+ ports (sorry, I know that the term is "cages" but I just can't) and a couple of copper 1Gbps ports.
So far I haven't found anything but I feel like my search will get motivated in the next couple of years since it feels like Ubiquiti has forgotten that EdgeRouter exists.
Do you have any rack form factor x86-type systems you like for VyOS?
for smaller or shallow stuff, supermicro, msi, tyan, asus
I have a couple of (fanless!) CRS305-1G-4S+IN[0] at home, one in my study and one in the utility room. They each connect with 10GbE fibre (or DAC) to ConnectX-3 cards in my PCs and servers.
Where I work, we use one of them as our main router with multiple peering sessions and two transit uplinks. According to Cacti, right now we're pushing about 30Gbps through the router.
That's what I'm looking to eventually replace, if Ubiquiti doesn't start up with software updates to the EdgeRouter line again. But I think that's the problem: the EdgeRouter line is so amazingly inexpensive for all of the power you get, there's no financial incentive for Ubiquiti to invest in it and all of the players with the "proper" routers--the Junipers and Ciscos and the like--start at three times the price of an ER-8-XG.
Indeed, not least on price. How much was your ER-8-XG? My CRS305-1G-4S+IN were about USD180 each.
EDIT: If there were a silent version of the CRS326-24S+2Q+RM[0][1] I'd have bought one already...
"The MikroTik CRS326-24S+2Q+RM is an insane switch. Its specs are relatively mundane by modern standards. It has 24x SFP+ 10GbE ports and 2x QSFP+ 40GbE ports making it not even as powerful as mainstream previous-generation switches like the QCT QuantaMesh T3048-LY8 that we installed in our lab years ago. Instead what makes the switch insane is that it offers all of that performance at $475"
[0] https://mikrotik.com/product/crs326_24s_2q_rm [1] https://www.servethehome.com/mikrotik-crs326-24s2qrm-review-...
any mikrotik CRS series has very limited routing/layer 3 ability compared to a CCR series. Different things for different purposes.
look at the logical block diagrams mikrotik provides of their crs series equipment. it's all a bunch of ethernet switch chips in a few blocks of 8 ports and then something like a single 1GbE link to the CPU. the moment you start telling it to do layer 3 things its capability is very limited.
However, neither of them will route 80 Gbps full duplex.
Then there is CCR2216-1G-12XS-2XQ (1x1Gbps, 12xSFP28, 2xQSPF28); this one is supposedly capable of routing shy of 200 Gbps @1518 packet size.
Edit: another thing on Mikrotik naming conventions: CRS = switches; CCR = routers.
At that scale you'd better have a redundant identical twin pair of routers with 1+1 or N+1 redundant everything (fans, power supplies, routing engines, etc) 24x7x365 service contract, and so on. Not something you can or should do with mikrotik.
but far pricier then mikrotik..
Both of these look fantastic. The second one, with the four SFP+ ports, looks like an almost drop-in replacement for the Infinity, particularly with its 16GB of RAM. (We use soft-reconfiguration inbound which bloats the amount of RAM needed for the tables.)
> However, neither of them will route 80 Gbps full duplex.
That's actually fine, at least for our needs. We only have 50Gbps of connectivity between peer, IXP, and transit links and today's 30Gbps is high because of end-of-month activities. We got the Infinity largely because it was the only EdgeRouter that could do what we needed. Like the gap between EdgeRouter Infinity and "every other router that can do what it does," there's a rather large gap in Ubiquiti's EdgeRouter line. The next one down in the list is the EdgeRouter-12 that is a small fraction of the capability of the Infinity.
> another thing on Mikrotik naming conventions: CRS = switches; CCR = routers
That's good to know. I hadn't started down the Mikrotik path yet but I'll give it a look. We have a leaf router at a small office where we experiment and maybe I can put one in there to start.
Thanks for all of the information!
200gbps is 20x this rate, or 16,254,876pps
This is 9% higher than the 10gbps packet rate for 'line rate', 14,880,952 pps, which can be done on a single core these days.
https://docs.fd.io/csit/rls1807/report/detailed_test_results...
It's in the first sentence of the post:
> Save space in your server room
if you have >10Gbps traffic flows and are putting the router and other hosting environment/linux things all together in one 1U piece of hardware as a single x86-64 server, that's a "too many eggs in one basket" problem.
also worth noting that many colo/hosting ISPs won't offer 25GbE circuits on SFP28 anyways, you can buy either a 10GbE transit link or 100GbE, or maybe 2x10GbE bundled together in a 802.3ad or similar.
However, it is not going to happen, it would be somewhere at bottom with priority. It was just an exercise, what could be done.
I simply cannot believe how terrible their IPv6 support is (still no connection tracking!), and plenty of weird glitches, etc.
But! Their hardware is very reasonably priced, and an excellent gateway to “real” networking equipment for the hobbyist. It’s unfair to compare it against Juniper and the likes: yes, it’s much better, but yes, the products are also 10x - 100x as expensive.
While everything that’s done in RouterOS can also be done under vanilla Linux, I buy Mikrotik precisely because I don’t want to build a custom Linux router. I want something that comes with a GUI, and I won’t have to spend too much time setting up.
Having said that, I would absolutely kill for an “escape” Linux shell. I know that RED supports ECN in Linux, please allow me to use it!
I see a list of connections under "IPv6 firewall" under the connections tab?
> and plenty of weird glitches
this bit however I agree with
7.1 is only required on their brand new router targeted at enthusiast home users. The RB5009, which specifically says it's targeting home labs and explicitly came with the caveat of 7.1 being the minimum version and there is no LTS in the 7.x branch as-of yet. This is the only product that requires the 7.x branch.
Everything else ships with 6.48.x LTS or 6.49.x Stable. Nearly all serious users are using the LTS branch. The 7.x branch is well known within the RouterOS community to not be "production" ready... although that's where new features and stuff are going. It will be, one day.
[1] https://help.mikrotik.com/docs/display/ROS/v7+Routing+Protoc...
Seriously? Is it not possible to have stateful firewall rules for IPv6 traffic? Or is it just NAT that won't work (I don't care about NAT, NAT can die)? I was considering getting a microtik router but this would be a dealbreaker.
JunOS is generally better than IOS(-XR), but it’s still got its sharp edges. VyOS / Vyatta are poor enough clones that they will bite and seriously suck to anyone who’s actually got real JunOS experience.
Let’s be real. The goal in improving network configuration standards is to suck less. That’s it. Everything in networks sucks. Anyone who tells you otherwise either lacks experience in general, lacks experience suffering at the bleeding edge, or lacks my cynicism and genuinely sees the world as a better place than I do (I envy them for any of the above)
Big difference between what you might get spending $15,000 for a Juniper MX204 running JunOS and a Mikrotik $800 router. I mentally categorize Mikrotik RouterOS and similar ultra low cost things in the same tier as VyOS. It's cheap but there are tradeoffs to going cheap. One has to understand the risks and tradeoffs of running a lot of your traffic or important things through cheap routers. Sometimes it's a risk worth taking.
Foundry, as we've seen, was a straight knockoff of the IOS 12.2/12.4 CLI and interface. Used plenty of Foundry switches in a previous role.
Everything does suck. Some things suck less. Sometimes you can pay money to get things that suck less.
And sometimes you pay more money and you're the one being made to do the sucking :-\
for a comparison, I once had an issue where both routers in a redundant setup failed within half an hour of each other. (was a pure coincidence, the setup was redundant). then, the sparefallback unit would not boot, and jtac send us a replacement within 3 HOURS...
Another point is the feature development: BGP implementation, in Mikrotik was single core only and this was a bottleneck especially when you want to calculate the full routing table. Everyone in the forum asked for this new feature, but Mikrotik always refuse to work on that.
And then there's Cisco
10Gb NIC's run around $100... and can't do any switching or routing. As mentioned, this card can offload 100% of routing needs from the server (ie. zero CPU usage on your server to make routing decisions), can switch at line speed (well above line speed actually, rated for 100Gbps throughput), plus the server can still use one of the ports for it's own needs. Sounds pretty powerful to me.
It's unlikely this is an interesting product for a home lab or business - it's likely more geared towards service providers. Still a pretty cool idea none-the-less, regardless of how you feel about routerOS.
Like this is cute and all, but kind of a weird target market.
The card actually has 4 "ports". 1 virtual port dedicated to management (via PCIe passthrough), 1 GBe port, and 2 SFP28 cages. Plenty for a cloud hosting provider. Both SFP28 cages, plus the virtual 1GBe port support passthrough via PCIe to the physical server.
That's just one use case. Another is a dedicated firewall for the actual physical server that's powering the thing, running at a full 25Gbps consuming zero CPU time on the server itself and zero U's of space... all for less than $199 street price. The card supports PCIe 8x passthrough, so the physical connection to the server is 64Gbps - way more than a single SFP28 cage can support.
Pretty slick...
And yes, I've done this stuff at very large scales.
I think people that feel this device is pointless just have not been in a situation where this device is exactly what they needed. It is a niche device, admittedly.
However, you have my attention - what device are you referring to that does this better and cheaper?
Seriously, there isn't a good problem here that this solution solves that isn't better done elsewhere.
Done in actual host CPU consumes resources.
Direct programming on a chipset is a lot more complicated than running an off the shelf router.
Yes this is a niche product - but your proposed alternatives are silly in most cases where just slapping a zero U device into an unused PCIe port is far less complicated, less expensive, and easier to maintain.
This thing costs less than $200, a one time cost. Just reading the Broadcom documentation alone will cost your organization more than that...
I do not like it, it is configurable only via web. No cli, no api, no ansible/terraform-like automation possible.
I've found UBNT's modern switches and routers to be nice from a UI perspective - but oh boy do they have strong opinions on how you should configure them. You have to jump through a ton of hoops to get the Dream Machine Pro to not be your actual gateway, for instance... tricking it into thinking it's the gateway and then unplugging that port, etc.
Mikrotik is happy to let you do whatever you want, to your detriment sometimes.
UBNT gear seems great for SMB/Home Labs where people just want it to work... Mikrotik is for those who want to tinker, and more power-oriented users looking for non-conventional setups.
RouterOS did have a learning curve, and there are some unexpected bugs, but compared to UBNT, I like it much more. Yes, it has more knobs, and they generally allow configuring that needs to be done.
This completely solves the issue, in a much better way than me just shipping a 2u server to a DC with a small micro router shoved inside the case and powered with a micro-usb cable haha.
Can't wait to buy one of these.
I’ve been wanting 10 Gbps networking for some time but I’ve been undecided how to best do that. Could I simply get this card, drop it in my FreeNas box, then plug my Arris S33 modem into the card, then the card to my network switch? Would the FreeNas host also get 10/25 Gbps virtually, or do I still need another card specifically for the FreeNas box?
Works fast and well. The fifth "management" 1GB port goes to my router, 1GB is way faster than my internet anyway.
Feels like the Holy Grail of backdoors.
Trust your vendors, lock down your network, be large enough to build your stack yourself; chose any 2...
[0]: https://www.youtube.com/watch?v=jmTwlEh8L7g "DEF CON 26 - Christopher Domas - GOD MODE UNLOCKED Hardware Backdoors in redacted x86"
It's a big bucket of additional weak links in my chain of security security. The whattabouttery in these replies isn't s good approach. It only takes one component to get hacked. More than doubling your surface area isn't something to do lightly.
When this can run non-Mikrotik open source software, this'll be great!
So just like any other major networking provider, including opensource projects?
Edit: never mind, it says it's primarily for home use
And this card is highly unlikely to be targeted for home use - mostly service providers doing routing within their private networks.
I wonder why they need to support 10 mbps port? Is it just because if the card supports 1000 mbps it will support 10mbps effortlessly?
Cisco has some switches that can't go down to 10, which makes it interesting when those show up on site and the HVAC system can't link up any more.
It used to be common run 10Mbs over coax too, back before Ethernet took over.
There's a 10BASE-T1 but this says it's very recent?
10BASE-T and 100BASE-TX are very similar except for the line encoding. One pair each way.
Coax uses one line, but that's not using twisted pairs at all.
https://en.wikipedia.org/wiki/BroadR-Reach
100Base-T1 has more in common with 1000BASE-T than the legacy standards, imagine if you took a single pair from the 4 needed to do Gigabit.
It amazes me how much misinformation gets posted on HN with convincing authority.
Coax is also two ”wires”, though obviously not twisted.
I used to do networking professionally too. Though it looks like I’ve gotten rather rusty on the basics.
https://en.wikipedia.org/wiki/Autonegotiation#Electrical_sig...
You could use the link pulses, but skip 10M support and leave out the 10M data encoding/decoding. Most likely, it's not a meaningful cost savings, although I've seen some devices that work at 10M, but don't turn on a link led.
Just the software doing the routing is not running on your main CPU, but on the CPU bundled on the board.
actual packet forwarding should be done in hardware, because software forwarding has atrocious performance in comparison.