2116 L3 HW Offload help

I have a configuration question about setting up a 2116 and L3 HW offload.

Currently I have a CCR2004-PC at one of our wireless towers. One sfp+ port is my uplink back to my core. The other sfp+ port connects to a Fiberbox Plus switch that runs our Tarana BNs.

I then have one copper port that connects to a backup microwave link for failover if the fiber fails. I then have two bonded interfaces made up of 2 copper ports each that connect to 2 POE switches that then feeds the Ubiquiti/Cambium APs.

CCR2004 is running OSPF to handle the failover between the fiber uplink and the licensed microwave link.

Here is a photo of the port layout. Each vlan on copper and sfpplus2 are routed subnets and have an IP address assigned.

SFPPlus 1 is connected to a rural co-op via 10G fiber. The co-op link is a ‘blind’ link and just carries my traffic (vlan) from this tower site back to our core.

Right the CCR2004 and all the copper switches reside at the top of the tower. Due to space limitations and some other reasons I want to replace the CCR2004 with a CCR2116 and then relocate the CCR2116 to the base of the tower where I have fiber running from the base to the top.

In this new setup I plan to use the CCR2116’s four SFP+ ports as follows.

  1. My uplink to the core via the co-op link.
  2. Connection to backup microwave link
  3. Connection to CRS309 switch that will replace the CCR2004 at the top of the tower.
  4. Connection to Fiberbox Plus switch at top of tower.

I know how to setup the CCR2116 if I ignore any of the L3 HW offload features of the 2116, but should I choose to use L3 offload I am not sure how best to setup the interfaces on the 2116.

I would like to setup the 2116 in a way that allows me to use L3 HW offload if I want to without any major changes to the configuration. Also want to mention that this is ISP traffic so most if not all traffic to/from the clients is routed out the uplink interface. Very little if any client to client traffic.

So for proper ability to use L3 offload should I put all 4 sfp+ ports of the 2116 into one bridge and then put the vlans on the bridge instead of the ethernet interfaces like I currently have on the 2004, or should I only put the 2 customer facing sfp+ port into a bridge and leave the uplink ports separate and configure like I have on the 2004?

I also found this post that confuses me more and if I understand it correctly, it is saying I should just configure things like I have it now without using any bridges at all and disable fasttrack to get L3 HW routing?

Also I have just a basic FW for the forward path on the CCR2004 router. Fasttrack for established/related. Standard accept for Estabilshed/related, and drops for Invalid and SNMP.