you need to lock pppoe server client ports 1-24, and allow for sfp1 port.
tried through bridge filters - works, but high load on the CPU - up to 100%.
configure ports 1-24 - slave, sfp1 - master - CPU load is low, but can not understand how in this mode pppoe configure filtering on ports 1-24?
config attached below.
vlan2 - vlan with users who want to protect from fake pppoe server
Ports 21-25 - trusted trunk ports are running genuine pppoe-server
please help me understand …
/interface vlan
add interface=ether24 l2mtu=1584 name=vlan2 vlan-id=2
add interface=ether24 l2mtu=1584 name=vlan3 vlan-id=3
/interface ethernet
set [ find default-name=ether1 ] master-port=ether24
set [ find default-name=ether2 ] master-port=ether24
set [ find default-name=ether3 ] master-port=ether24
set [ find default-name=ether22 ] master-port=ether24
set [ find default-name=ether23 ] master-port=ether24
/interface ethernet switch egress-vlan-tag
add tagged-ports=ether21,ether22,ether23,ether24,sfp1 vlan-id=2
add tagged-ports=ether21,ether22,ether23,ether24,sfp1 vlan-id=3
/interface ethernet switch ingress-vlan-translation
add customer-vlan-format=untagged-or-tagged new-customer-vid=2 ports=\
ether1,ether2,ether3,ether4,ether5,ether6 sa-learning=yes \
service-vlan-format=untagged-or-tagged