Manual

CRS317-1G-16S+RM

Sixteen 10 Gbit SFP+ cages in 1U: the fibre switch for a rack full of servers.

The CRS317-1G-16S+RM is a 1U switch with sixteen 10 Gbit SFP+ cages and one gigabit copper port. It belongs in a rack where servers, storage and other switches all want a 10 Gbit connection. When the CRS309 becomes too small, this is the next device.

There is no Wi-Fi in it. This is a switch in a rack. Access points live elsewhere in the network, behind a router or a PoE switch.

The ports

  • sfp-sfpplus1 through sfp-sfpplus16: sixteen 10 Gbit SFP+ cages. Everything doing serious traffic belongs here.
  • ether1: one gigabit copper port. Your management port: plug in a laptop and you can reach the switch, even when something goes wrong with the fibre.

There is no PoE-out on this model, so the PoE-out per port field does not appear. And because the catalogue knows this as a switch, no WAN port is recorded: in the Switch role nothing is routed.

With sixteen identical ports, the layout is the real work. Which port becomes your trunk to the router, which ports are access ports, and which you leave switched off. The Switch role puts the last port on trunk and the rest on access by default; you change that at the VLAN step. Ports with nothing on them can be switched off in Bridge and ports. See VLANs and Bridge and ports.

To bundle two cages towards the same far end, that is a bond with LACP; see Bonding. For jumbo frames towards storage, see MTU.

What the tool does with it

The catalogue knows this model as a switch. The roles that route are therefore greyed out with the message "This is a switch": Home router, Office router with VLANs, VPN gateway, Router + CAPsMAN and Hotspot. Access point, CAP, Wi-Fi repeater and Wireless CPE are greyed out with "No wifi radio", and LTE / 5G router with "No LTE modem".

What is left is Switch, plus Harden only (baseline) for a switch that already runs. The Switch role writes: every port in one bridge with RSTP, a VLAN table through /interface bridge vlan, a static management address on the management VLAN with a gateway towards your router, and no DHCP, NAT or routing. Only a firewall that protects the device itself.

The Hardware offloading (switch chip) toggle under Ports is on by default and should stay on. This model is not listed with hw_vlan: switch-menu, so bridge VLAN filtering is the right route here; you do not get the warning about losing offload on this device.

What is inside

The catalogue records ARM 32bit, 1 GB of memory, the 98DX8216 switch chip and RouterOS licence level 6. A gigabyte of memory and the top licence level are ample for a switch's work. The small-board note never appears here.

Where it runs out: in this role it is a layer-2 device. Routing between VLANs is your router's job. RSTP is on, which is sensible in a rack where someone will eventually make a loop, but it does not replace a design; see A ring with RSTP if you put a loop in deliberately. Our catalogue records no throughput figures, so this page does not quote any.

The quickest route to a working configuration

  1. Pick One device and search for CRS317.
  2. Pick the Switch role and walk through the wizard.
  3. At the VLAN step, decide which port becomes the trunk and which VLAN is your management VLAN.
  4. Fill in the management address and gateway, and check them before you paste.
  5. Set an admin password, reset the device and paste the script. See Using the script.

If this switch sits in a rack with more equipment, Multiple devices is faster: you draw the cables on the network board, the cabling decides the trunks, and the site checks report whether a VLAN stops halfway along a cable.

What trips people up

  • Empty cages. Without a matching module or DAC a port does not come up. Check with /interface ethernet print.
  • Modules that do not match. Two ends with different optics, or a DAC the far end will not accept, give you a port that stays silent.
  • Using the gigabit port as an uplink. ether1 is one gigabit and is meant for management.
  • Locking yourself out. After pasting, the switch is only reachable on the management address in the management VLAN. Keep MAC-WinBox or a serial connection in reserve. See Switch unreachable.
  • The management VLAN untagged on an ordinary port. Send it tagged towards your router, not untagged to a server.

Want to try it right away? Open the configurator