even if it remotely possible don’t do it because macsec and vxlan encapsulation/decapsulation is process by CPU for now, some of the marvel hardware is capable but the codebase of mikrotik does not support it that’s what I’m reading here in the forum all the time look at what post https://forum.mikrotik.com/viewtopic.php?p=1076484&sid=86b3def1ac3183e7403f03c37bd2846d#p985747