MikroTik is unusual among network vendors in publishing a throughput table for every board it sells, measured across packet sizes and configuration modes. That transparency is genuinely useful, and it is also the thing buyers misread most often. This guide explains what those numbers mean, then maps the current tiers onto the jobs people actually buy them for.
Once you have chosen a board, follow the MikroTik router setup checklist for the first login, WAN connection, updates and verification.
How to read MikroTik’s published numbers
Every product page carries a test-results table. The critical detail is that the headline figure is the fast path result at a 1518-byte frame size, with no firewall rules, no queues, and nothing else in the way.
Two consequences follow.
First, large frames flatter the Mbps column. A router forwards packets, not bytes, so the packets-per-second figure is the real capacity measure. At 1518 bytes each, 148,400 packets per second works out to roughly 1,802 Mbps; the same packet rate carrying 64-byte frames is worth about 76 Mbps. Traffic mixes on a real link sit somewhere between, which is why MikroTik publishes several frame sizes and why the small-frame rows are the honest ones for VoIP, gaming, or anything transactional.
Second, the fast-path row is a ceiling, not an expectation. Add connection tracking, filter rules, simple queues, or IPsec and packets take a slower route through the system. MikroTik publishes separate rows for exactly this reason, and the gap between them is often large. The mechanism behind that gap is worth understanding before you spend money, and it is covered in why RouterOS throughput drops when CPU load climbs.
The current tiers, side by side
All figures below are taken from MikroTik’s own product pages: suggested prices as published by MikroTik, and routing throughput from the fast-path, 1518-byte row of each board’s test-results table. Street prices vary by region and reseller.
| Model | CPU | Cores / clock | RAM | Ports | Routing, fast path (1518 B) | Suggested price |
|---|---|---|---|---|---|---|
| hEX (RB750Gr3) | MT7621A | 2 cores, 880 MHz | 256 MB | 5x 1G | 148.4 kpps / 1,802 Mbps | $59.95 |
| hEX S (RB760iGS) | MT7621A | 2 cores, 880 MHz | 256 MB | 5x 1G, 1x SFP | 148.4 kpps / 1,802 Mbps | $79.00 |
| hAP ax3 | IPQ-6010 | 4 cores, up to 1800 MHz | 1 GB | 4x 1G, 1x 2.5G, Wi-Fi 6 | 218.9 kpps / 2,658 Mbps | $139.00 |
| RB5009UG+S+IN | 88F7040 | 4 cores, up to 1400 MHz | 1 GB DDR4 | 7x 1G, 1x 2.5G, 1x SFP+ | 811.2 kpps / 9,851 Mbps | $219.00 |
| CCR2004-1G-12S+2XS | AL32400 | 4 cores, 1700 MHz | 4 GB ECC | 1x 1G, 12x SFP+, 2x SFP28 | 3,138.7 kpps / 38,116 Mbps | $595.00 |
| CCR2216-1G-12XS-2XQ | AL73400 | 16 cores, 2000 MHz | 16 GB | 1x 1G, 12x 25G SFP28, 2x 100G QSFP28 | 6,168.5 kpps / 74,910 Mbps | $2,795.00 |
The jumps are not linear with price. hEX to hAP ax3 is 2.3x the money for roughly 1.5x the packet rate, plus Wi-Fi 6 and a 2.5G port. hAP ax3 to RB5009 is 1.6x the money for 3.7x the packet rate and a 10G SFP+ cage, which makes that step the sharpest value inflection in the line-up for anyone routing more than a gigabit. Past it the curve turns the other way: CCR2004 is 2.7x the RB5009 price for 3.9x the packet rate, and CCR2216 is 4.7x the CCR2004 price for 2.0x the packet rate. At that end you are buying port density, memory, and 25G or 100G optics rather than forwarding capacity per dollar.
Matching the tier to the job
A home connection up to roughly 500 Mbps, wired, with a separate access point. The hEX is enough, and the hEX S is the same board with an SFP cage and PoE-out on port five. Buy the S variant only if you need fibre in or need to power a single downstream device. Neither has Wi-Fi.
A home connection with Wi-Fi in one unit. The hAP ax3 combines Wi-Fi 6 on both bands, a 2.5G port and 1 GB of RAM. The cited product specifications list MMIPS architecture and 256 MB RAM for the hEX (RB750Gr3) and hEX S (RB760iGS). Architecture and RAM are separate specifications: RAM capacity alone does not establish RouterOS container compatibility. These specifications apply to those two product codes, not every device sold under the hEX name. Check the exact model’s architecture and supported packages before planning a container workload.
A small office, a homelab with VLANs, or a symmetric multi-gigabit service. The RB5009 is the board most people should be looking at. Seven gigabit copper ports plus a 2.5G copper port, an SFP+ cage for a 10G uplink or a link to a switch, passive cooling, and a packet rate with real headroom above a 1 Gbps service even once firewall rules are in play: MikroTik’s table puts it at 811.2 kpps on the fast path and still 771.2 kpps with 25 IP filter rules loaded. Note that the hAP ax3 carries the same 1 GB of RAM for $80 less, so the RB5009 is bought for its ports and its packet rate, not for its memory.
An edge router, a small ISP, or anything terminating BGP. The CCR2004 tier is where SFP+ density and ECC memory start; the CCR2216 is where 25G and 100G cages and 16 GB of RAM do. Memory is the specification that matters at this end, and it is the one figure nobody can look up: MikroTik publishes a throughput table for every board it sells but no per-route memory figure for RouterOS v7, so BGP sizing is a planning exercise rather than a lookup. Every full feed you accept is another copy of the table held in RAM, and a router that exhausts memory mid-convergence does not fail gracefully. Size for headroom above the number of feeds you expect, then measure the real footprint on your own hardware before adding another session.
The RouterOS FastPath and switch-chip sizer on this site takes a hardware tier, a FastTrack state, a switch-offload state, and a BGP feed count, and reports the resulting packet ceiling plus a memory-headroom estimate, which is a quicker way to sanity-check a shortlist than reading five product pages side by side.
Specifications that matter more than the headline
Switch chip versus CPU. Hardware bridge offload depends on the exact model, ports and configuration. Do not assume every router in the table can switch Layer 2 traffic in hardware, or use its fast-path routing result as a switching guarantee. Check the model’s block diagram and the switch-chip feature matrix before planning a bridge. The model-specific conditions are covered in VLAN filtering on RouterOS bridges. Where offload is unavailable, size the bridge against the model’s published bridging test results rather than assuming wire-speed forwarding.
Port speed versus port count. A 2.5G or SFP+ port is not just about a faster internet service. It is also how you avoid a single gigabit uplink becoming the bottleneck between the router and a switch that aggregates everything else.
RAM. The listed hEX models have 256 MB, the hAP ax3 and RB5009 have 1 GB, and the CCR2004 has 4 GB with ECC. These are capacity specifications, not guarantees that a particular workload or RouterOS package will run. Check package compatibility separately, then size memory for the intended workload.
Cooling and noise. Everything through the RB5009 is passively cooled and silent. Rack-mount CCR models have fans, and while some run them slowly at low load, that is a decision to make deliberately if the device lives in an office rather than a rack room.
PoE. Passive PoE-out on a single port, as on the hEX S, powers one access point. It is not a substitute for a PoE switch, and passive PoE is not the same standard as 802.3af/at, so check what the powered device expects before relying on it.
The mistakes that cost money
Buying on the Mbps column alone, without checking the packet rate at a realistic frame size. Sizing against the fast-path row and then building a configuration that disables the fast path. Under-buying RAM because the routing figures looked adequate. Assuming a Wi-Fi model is a downgrade on the routing side when a hAP ax3 outruns both hEX variants. And buying a CCR for a gigabit home connection, where the throughput is wasted and the fan is not.
Whichever board you settle on, the configuration order once it arrives is the same, and it is worth following before the device sees an untrusted network: see securing a new RouterOS box.