If a bridge has an H flag but inter-VLAN routing still loads the CPU, check the model’s L3 hardware-offload support. An RB5009 bridge can switch in hardware without providing L3HW routing. Enabling another bridge option cannot add an unsupported routing feature.
Scope: RouterOS switch/bridge offload and IPv4 FastTrack. Hardware capabilities depend on the exact model and switch chip.
H is missing on some bridge ports
| Model | Documented switch path | Practical boundary |
|---|---|---|
| RB5009 series | 88E6393X: ether1–8 and SFP+ | Bridge/VLAN offload; not in the documented L3HW supported-device list |
| RB4011iGS+ | Two RTL8367 groups: ether1–5 and ether6–10 | Cross-chip traffic and SFP+ are not one hardware bridge path |
| CCR2004-16G-2S+ | Two 88E6191X groups: ether1–8 and ether9–16 | Not listed in the L3HW supported-device table |
| hEX RB750Gr3 / hEX S RB760iGS | MT7621: ether1–5 | SFP on this hEX S is outside the listed switch group |
| hEX refresh E50UG | EN7523: ether2–5 | ether1 is outside the listed switch-port group |
| hAP ax² / hAP ax³ | IPQ-PPE: ether1–5 | IPQ-PPE caveat: retain RSTP/software forwarding |
| L009 | 88E6190: ether2–8 and SFP | ether1 is not in this switch group |
Use the switch-chip support matrix to choose ports in the same supported switch group. If a port is outside that group, move the link to a suitable free port and preserve its VLAN configuration. Most supported chips offload only one bridge; separate bridges can leave another path on the CPU.
Bridge offload works, but routed traffic still uses the CPU
| Exact model examples | L3HW | Hardware FastTrack / NAT |
|---|---|---|
| CRS326-24G-2S+, CRS305-1G-4S+, CRS328-24P-4S+ | Listed for IPv4/IPv6 routing | Not supported in the current L3HW table |
| CRS310-8G+2S+ | Listed for IPv4/IPv6 routing | Not supported in the current L3HW table |
| CRS309-1G-8S+, CRS317-1G-16S+ | Listed | Supported subject to feature/resource limits |
| CRS326-24S+2Q+ | Listed; different chip from CRS326-24G | Supported subject to feature/resource limits |
| CCR2116-12G-4S+, CCR2216-1G-12XS-2XQ | Listed | Supported subject to feature/resource limits |
The full model suffix matters: CRS326-24G and CRS326-24S use different hardware. Route and connection-table limits can also move otherwise eligible traffic back to the CPU.
Read the active path
/system/resource/print
/interface/ethernet/switch/print
/interface/bridge/port/print
/interface/bridge/vlan/print
/ip/firewall/filter/print stats where action=fasttrack-connectionCheck the bridge H flag on the actual ingress/egress ports, their switch-chip membership and the VLAN path. For hAP ax IPQ-PPE, the bridge documentation warns about the protocol-mode=none offload path and recommends retaining RSTP/software forwarding or disabling offload. Removing loop protection to obtain H is a poor trade.
Measure forwarding without bypassing policy
If a deny rule stops working after enabling full L3HW, send that routed path through the CPU firewall using the documented L3HW port design. Disabling ingress offload alone is insufficient; the documentation’s CPU-firewall example disables offload on the egress-facing port. Apply that design to the actual traffic direction, then retest the deny.
Measure throughput between external hosts, with Torch/sniffer stopped.
During the transfer run /system/resource/print and read cpu-load. Run /interface/print stats-detail before and after: compare rx-byte and tx-byte on the physical ingress/egress ports. Rising tx-queue-drop indicates interface-queue drops; an increase in link-downs records link interruptions. These counters include all traffic on that interface.
Also attempt a connection that policy must deny; restore the changed bridge/switch/port settings if it succeeds. A router-generated bandwidth test adds CPU load and is a different measurement.