MikroTik at 100% CPU: find the cause and fix it
Last updated: 2 October 2026
A router at 100% CPU is slow for everyone: pages hang, Winbox lags, customers get disconnected. RouterOS can tell you which part of the system is using the processor, and each answer points to a short list of causes.
1. Measure
/system resource print
/system resource cpu print
/tool profile/system resource print shows the load and free memory. /tool profile (Winbox: Tools → Profile) lists what the processor is busy with. Let it run for half a minute and read the top lines:
| Top line in profile | Look at |
|---|---|
dns | DNS open to the internet |
firewall | Too many rules, layer7, an attack |
queuing | Many queues, no FastTrack |
networking, ethernet | Simply a lot of traffic, or connection tracking under attack |
bridging | A loop, or bridged traffic without hardware offload |
logging | Too much being logged |
management | Winbox windows, scripts, many SNMP or API requests |
ppp | Many PPPoE sessions connecting at once |
DNS open to the internet
The classic. The router answers DNS questions from the whole internet and is used in attacks on others. Check for DNS traffic arriving on the WAN, then block it:
/tool torch interface=ether1 port=53
/ip firewall filter add chain=input in-interface=ether1 protocol=udp dst-port=53 action=drop place-before=0
/ip firewall filter add chain=input in-interface=ether1 protocol=tcp dst-port=53 action=drop place-before=0Details in DNS setup.
Many firewall rules and layer7
Every new packet is compared with your rules from the top down. Hundreds of rules, and above all layer7 patterns, are expensive.
/ip firewall filter print stats
/ip firewall mangle print stats
/ip firewall layer7-protocol print- Keep the rule that accepts
established,relatedconnections at the top of each chain, so most packets stop there. - Replace long runs of similar rules with one rule and an address list.
- Remove layer7 rules. They cannot read HTTPS anyway; see how to block websites for what works.
- Delete rules whose counters stay at zero.
Queues without FastTrack
With FastTrack, established connections skip most of the firewall and all queues, which is why a home router copes with a fast line. The moment you disable it to make queues work, every packet takes the slow path. On a small router with a fast line, that alone can reach 100%.
/ip firewall filter print where action=fasttrack-connection
/queue simple print count-only- If you do not limit speeds on this router, turn FastTrack back on:
/ip firewall filter enable [find action=fasttrack-connection]. - If you do, use fewer, simpler queues: one PCQ queue for a whole network instead of hundreds of single ones. See bandwidth limit per user.
- If the router is simply too small for the line and the number of customers, no setting fixes that.
Connection tracking under attack
/ip firewall connection tracking print
/ip firewall connection print count-onlyA small office has a few thousand connections. Tens or hundreds of thousands mean a flood from outside or an infected device inside. From outside: make sure the input chain drops everything unasked from the WAN (basic firewall). From inside: find the device with Torch (who is using the bandwidth) and take it off the network.
Logging
A firewall rule with log=yes on busy traffic, or debug topics left on, writes thousands of lines a second.
/system logging print
/ip firewall filter print where log=yesTurn off log on rules you are no longer studying and remove debug logging rules. Logging to disk is costlier than logging to memory.
Bridge loops
Two bridge ports joined through a cable or a switch make traffic circle endlessly. The whole network stalls and the log shows it:
/log print where message~"loop"
/interface print stats
/interface bridge set [find] protocol-mode=rstpUnplug ports one at a time until the load drops, then find the extra cable. More in bridge setup.
Other things worth a look
- Torch or a packet sniffer left open in a Winbox window somewhere.
- A script in a tight loop:
/system script job print. - An old RouterOS version: upgrade.
- Unknown schedulers or scripts: the router may have been broken into. See how to secure the router.
Where RadiusNest fits
RadiusNest does not make a router's processor faster, and the speed limit for each hotspot or PPPoE customer is still a queue on your router. What it does remove is the load of expiry scripts and schedulers that walk through every user every few minutes: packages, data counts and end dates are checked centrally instead of by scripts on the router.
Start the free trial See pricing
Questions and answers
Is 100% CPU on one core a problem?
It can be. Some work, such as one PPPoE line or a queue, runs on one core. If that core is full, traffic is limited even when the average looks low.
Does turning off FastTrack raise CPU usage?
Yes, clearly. All traffic then passes through the full firewall and the queues. It is needed for queues and marking rules, so size the router for it.
Why is my MikroTik CPU high with almost no traffic?
Look at /tool profile. The usual answers are DNS requests from the internet, heavy logging, a bridge loop or a script that never ends.