pjhtech Tools
MikroTik

MikroTik Hardware Offload Missing or Firewall Rules Bypassed

Check model and port-group limits when H is missing, routing loads the CPU, or full L3 hardware offload bypasses firewall rules.

If a bridge has an H flag but inter-VLAN routing still loads the CPU, check the model’s L3 hardware-offload support. An RB5009 bridge can switch in hardware without providing L3HW routing. Enabling another bridge option cannot add an unsupported routing feature.

Scope: RouterOS switch/bridge offload and IPv4 FastTrack. Hardware capabilities depend on the exact model and switch chip.

H is missing on some bridge ports

ModelDocumented switch pathPractical boundary
RB5009 series88E6393X: ether1–8 and SFP+Bridge/VLAN offload; not in the documented L3HW supported-device list
RB4011iGS+Two RTL8367 groups: ether1–5 and ether6–10Cross-chip traffic and SFP+ are not one hardware bridge path
CCR2004-16G-2S+Two 88E6191X groups: ether1–8 and ether9–16Not listed in the L3HW supported-device table
hEX RB750Gr3 / hEX S RB760iGSMT7621: ether1–5SFP on this hEX S is outside the listed switch group
hEX refresh E50UGEN7523: ether2–5ether1 is outside the listed switch-port group
hAP ax² / hAP ax³IPQ-PPE: ether1–5IPQ-PPE caveat: retain RSTP/software forwarding
L00988E6190: ether2–8 and SFPether1 is not in this switch group

Use the switch-chip support matrix to choose ports in the same supported switch group. If a port is outside that group, move the link to a suitable free port and preserve its VLAN configuration. Most supported chips offload only one bridge; separate bridges can leave another path on the CPU.

Bridge offload works, but routed traffic still uses the CPU

Exact model examplesL3HWHardware FastTrack / NAT
CRS326-24G-2S+, CRS305-1G-4S+, CRS328-24P-4S+Listed for IPv4/IPv6 routingNot supported in the current L3HW table
CRS310-8G+2S+Listed for IPv4/IPv6 routingNot supported in the current L3HW table
CRS309-1G-8S+, CRS317-1G-16S+ListedSupported subject to feature/resource limits
CRS326-24S+2Q+Listed; different chip from CRS326-24GSupported subject to feature/resource limits
CCR2116-12G-4S+, CCR2216-1G-12XS-2XQListedSupported subject to feature/resource limits

The full model suffix matters: CRS326-24G and CRS326-24S use different hardware. Route and connection-table limits can also move otherwise eligible traffic back to the CPU.

Read the active path

Read-only
/system/resource/print
/interface/ethernet/switch/print
/interface/bridge/port/print
/interface/bridge/vlan/print
/ip/firewall/filter/print stats where action=fasttrack-connection

Check the bridge H flag on the actual ingress/egress ports, their switch-chip membership and the VLAN path. For hAP ax IPQ-PPE, the bridge documentation warns about the protocol-mode=none offload path and recommends retaining RSTP/software forwarding or disabling offload. Removing loop protection to obtain H is a poor trade.

Measure forwarding without bypassing policy

If a deny rule stops working after enabling full L3HW, send that routed path through the CPU firewall using the documented L3HW port design. Disabling ingress offload alone is insufficient; the documentation’s CPU-firewall example disables offload on the egress-facing port. Apply that design to the actual traffic direction, then retest the deny.

Measure throughput between external hosts, with Torch/sniffer stopped.

During the transfer run /system/resource/print and read cpu-load. Run /interface/print stats-detail before and after: compare rx-byte and tx-byte on the physical ingress/egress ports. Rising tx-queue-drop indicates interface-queue drops; an increase in link-downs records link interruptions. These counters include all traffic on that interface.

Also attempt a connection that policy must deny; restore the changed bridge/switch/port settings if it succeeds. A router-generated bandwidth test adds CPU load and is a different measurement.

References