Manual

CCR2116-12G-4S+

Thirteen gigabit ports, four SFP+ cages and 16 GB of memory: a Cloud Core Router for the rack.

The CCR2116-12G-4S+ is a Cloud Core Router for a rack: thirteen gigabit ports, four 10 Gbit SFP+ cages and 16 GB of memory. It belongs where the traffic is serious and the router is not allowed to give up: the edge of a company network, a small provider, a datacentre rack, a building with several uplinks.

There is no Wi-Fi in it. No radios, no antennas, and that is the point: this is a routing device in a rack, with access points elsewhere in the network. There is no LTE modem either.

The ports

  • ether1 through ether13: thirteen gigabit ports. ether1 is the default WAN port as the catalogue records it.
  • sfp-sfpplus1 through sfp-sfpplus4: four 10 Gbit SFP+ cages. These are the ports the real traffic goes over: uplinks, a link to the core switch, a server or a second router.

There is no PoE-out on this model, so the PoE-out per port field does not appear. Access points and cameras get their power elsewhere, from a PoE switch or an injector.

The usual split is: the SFP+ cages for uplinks and the link to your switches, the gigabit ports for devices that do not need 10 Gbit, or for management. Thirteen copper ports does not mean all thirteen have to do something; ports with nothing on them can be switched off in Bridge and ports. See Bridge and ports.

For several uplinks with failover or sharing, see Multiple WAN connections. To bundle two SFP+ cages towards the same switch, that is a bond; see Bonding.

What is inside

The catalogue records ARM 64bit, 16 GB of memory, the 98DX3255 switch chip and RouterOS licence level 6. Sixteen gigabytes is a different order of magnitude from the boards measured in megabytes: memory will not be your limit here, not even with a full BGP table or containers alongside. Level 6 puts no limit on tunnels, sessions or routing daemons.

The catalogue sets this model's default configuration to router-ccr: it is a router, not a switch, so the roles that route stay available. For VLANs there is no hw_vlan: switch-menu, so you do not get the note that bridge VLAN filtering turns hardware offload off. The small-board note obviously never appears here either.

We say nothing about throughput: our catalogue records no figures for this model, and a number from a datasheet says little about your rules and your traffic. Measure it on your own device.

What it is good at, and where it runs out

Good at: routing with a lot of sessions, dynamic routing, tunnels, and several 10 Gbit links at once. The combination of 16 GB of memory and licence level 6 means the limits are not in the device but in what you ask of it.

Where it runs out: this is not a switch. Traffic that only has to move from port to port belongs on a switch, not on a router at this price. And as everywhere, anything that has to go through the CPU, tunnels and queue trees first, is slower than what the ports could carry.

Which roles fit

  • Core router: the role this device is meant for. Routed interfaces without a bridge, OSPF or BGP, static routes, a strict management ACL, no NAT and no fasttrack. See OSPF and BGP.
  • Office router with VLANs: usable when this router also handles a building's VLANs.
  • VPN gateway: with this CPU and licence level a serious number of tunnels is within reach. See Site-to-site tunnels.
  • Harden only (baseline): for a CCR that already runs and that you only want to lock down.

Greyed out: Access point, CAP, Wi-Fi repeater and Wireless CPE, with the message that there is no Wi-Fi radio, and LTE / 5G router, because there is no modem. The Switch role is still offered, because the configurator blocks it nowhere, but it is not meant for this device.

The quickest route to a working configuration

  1. Pick One device and search for CCR2116.
  2. Pick Core router if this device routes without a bridge, or Office router with VLANs if it also handles a building's VLANs.
  3. At the routing step: fill in the addresses per interface, a loopback if you use one, and OSPF or BGP if you run them.
  4. Restrict management access to your management network. On a device with public uplinks that is not a luxury. See Management access.
  5. Set an admin password, reset the device and paste the script. See Using the script.

For a setup across several sites, see Hub and spokes and OSPF between sites.

What trips people up

  • Using it as a switch. You can, but then you are buying an expensive router to do what a CRS317 does better and cheaper.
  • Empty SFP+ cages. Without a matching module or DAC such a port does not come up. Check with /interface ethernet print.
  • Management on a public port. On devices like this a strict management ACL is the first thing you arrange, not the last. See Security checks.
  • Turning fasttrack on in a core setup. The Core router role deliberately leaves fasttrack and NAT off. That is not a mistake.
  • Locking yourself out. Without a bridge there is no port that works by itself. Think about your management address in advance and keep a serial connection in reserve. See Locked out.

Want to try it right away? Open the configurator