And real equipment does MPLS forwarding in hardware. Something Mikrotik should try to achieve instead of only HW-L3 routing.Most carriers use MPLS internally
That often solved with SNMP counters and PVLAN/NNI-UNI for customer to customer isolation.statistics collection (usage), and Layer 2 client isolation.
Users that don't know why they need a router of their own - usually sticks with the ISP provided one.But you can ask "select your country and ISP from this list".
Then you are doing it wrong. You should do the configuration under /interface ethernet switchAbut we stuck on the switch itself as the hardware offload turned-off when we activated vlan-filtering.
Fun feature, but why? Who absolutly needs valid certificates for the www-ssl service, and can not do it separatly?!) added support for Let's Encrypt certificate generation;
/ip firewall nat add action=dst-nat chain=dstnat dst-port=80 in-interface-list=WAN log=yes protocol=tcp to-addresses=192.168.1.20
There is for certainly many millions of dollars put in to R&D there.