Can't Access RB5009 LAN IPs from CRS309

Hello,
I Have a RB5009 connected to a CRS309 via the SFP+ port on the RB5009.

I have a seemingly default configuration on each. What I am noticing is that when I am plugged directly into the RB5009 via a 1G Ethernet port, I can access the RB5009, CRS309, and all my IPMI IPs by their LAN IP just fine. But from the CRS309 with my PC on a SFP+ port, I cannot winbox into the router or the switch by their IPs and 1G Ethernet device IPs from the RB5009 are inaccessible.

RB5009 config:

# may/19/2024 11:41:11 by RouterOS 7.6
# software id = 
#
# model = RB5009UG+S+
# serial number = 123434564567
/interface bridge
add admin-mac=AA:BB:CC:DD:EE:FF auto-mac=no comment=defconf name=bridge
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp ranges=192.168.0.10-192.168.0.254
/ip dhcp-server
add address-pool=dhcp interface=bridge name=defconf
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=sfp-sfpplus1
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/ip address
add address=192.168.0.1/24 comment=defconf interface=bridge network=192.168.0.0
/ip dhcp-client
add comment=defconf interface=ether1
/ip dhcp-server lease
add address=192.168.0.50 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.4 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.15 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.30 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.10 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.2 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.25 comment=gitlab mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.22 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.51 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.3 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.14 mac-address=AA:BB:CC:DD:EE:FF server=defconf
add address=192.168.0.254 comment=CRS309 mac-address=AA:BB:CC:DD:EE:FF server=defconf
/ip dhcp-server network
add address=192.168.0.0/24 comment=defconf dns-server=192.168.0.1 gateway=192.168.0.1 netmask=24
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.0.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat disabled=yes dst-port=21381 in-interface=ether1 protocol=tcp to-addresses=192.168.0.2
add action=dst-nat chain=dstnat disabled=yes dst-port=28852,8075,20560 in-interface=ether1 protocol=tcp to-addresses=192.168.0.2
add action=dst-nat chain=dstnat disabled=yes dst-port=7707,7708,7717,28852,8075,20560 in-interface=ether1 protocol=udp to-addresses=192.168.0.2
add action=dst-nat chain=dstnat disabled=yes dst-port=32400 in-interface=ether1 protocol=tcp to-addresses=192.168.0.3
add action=dst-nat chain=dstnat disabled=yes dst-port=49161 in-interface=ether1 protocol=tcp to-addresses=192.168.0.3
add action=dst-nat chain=dstnat disabled=yes dst-port=8211 in-interface=ether1 protocol=tcp to-addresses=192.168.0.248
add action=dst-nat chain=dstnat disabled=yes dst-port=8211 in-interface=ether1 protocol=udp to-addresses=192.168.0.248
add action=dst-nat chain=dstnat disabled=yes dst-port=26900 in-interface=ether1 protocol=tcp to-addresses=192.168.0.47
add action=dst-nat chain=dstnat disabled=yes dst-port=26901 in-interface=ether1 protocol=udp to-addresses=192.168.0.47
add action=dst-nat chain=dstnat disabled=yes dst-port=26902 in-interface=ether1 protocol=udp to-addresses=192.168.0.47
add action=dst-nat chain=dstnat disabled=yes dst-port=26903 in-interface=ether1 protocol=udp to-addresses=192.168.0.47
add action=dst-nat chain=dstnat disabled=yes dst-port=26900 in-interface=ether1 protocol=udp to-addresses=192.168.0.47
add action=dst-nat chain=dstnat disabled=yes dst-port=4001 in-interface=ether1 protocol=tcp to-addresses=192.168.0.3
add action=dst-nat chain=dstnat disabled=yes dst-port=4001 in-interface=ether1 protocol=udp to-addresses=192.168.0.3
/ip firewall service-port
set ftp disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=ether1 type=external
/ipv6 dhcp-client
add add-default-route=yes interface=ether1 pool-name=verizon_ipv6 request=address,prefix use-interface-duid=yes
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/system clock
set time-zone-name=America/New_York
/system ntp client
set enabled=yes
/system ntp client servers
add address=time-a-g.nist.gov
add address=time-b-g.nist.gov
add address=time-c-g.nist.gov
add address=time-d-g.nist.gov
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN

CRS309

# 2024-05-19 11:50:20 by RouterOS 7.12.1
# software id = 1234-1234
#
# model = CRS309-1G-8S+
# serial number = 123412341234
/interface bridge
add admin-mac=AA:BB:CC:DD:EE:FF auto-mac=no comment=defconf name=bridge
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge comment=defconf interface=ether1
add bridge=bridge comment=defconf interface=sfp-sfpplus1
add bridge=bridge comment=defconf interface=sfp-sfpplus2
add bridge=bridge comment=defconf interface=sfp-sfpplus3
add bridge=bridge comment=defconf interface=sfp-sfpplus4
add bridge=bridge comment=defconf interface=sfp-sfpplus5
add bridge=bridge comment=defconf interface=sfp-sfpplus6
add bridge=bridge comment=defconf interface=sfp-sfpplus7
add bridge=bridge comment=defconf interface=sfp-sfpplus8
/interface list member
add interface=ether1 list=WAN
add interface=sfp-sfpplus1 list=LAN
add interface=sfp-sfpplus2 list=LAN
add interface=sfp-sfpplus3 list=LAN
add interface=sfp-sfpplus4 list=LAN
add interface=sfp-sfpplus5 list=LAN
add interface=sfp-sfpplus6 list=LAN
add interface=sfp-sfpplus7 list=LAN
add interface=sfp-sfpplus8 list=LAN
/ip dhcp-client
add interface=bridge
/system clock
set time-zone-name=America/New_York
/system identity
set name=MikroTik-SFP
/system note
set show-at-login=no
/system routerboard settings
set boot-os=router-os enter-setup-on=delete-key
/system swos
set identity=MikroTik static-ip-address=192.168.0.15

Thanks a lot for taking a look, this problem has been very frustrating as I cannot find any issue with the settings.