CRS and Port Isolation

Looking for a simple way to do this yet maintain full 1Gbps speed on CRS125-24G-1S-IN.

Hypothetically. I have 2 PPPoE servers. I want to plug one into CRS port 1 and the other in 2. I want to plug all my backhauls and APs into all other ports, 3 through 24 ports.

I want ports 1 and 2 to be able to talk to any other port they want. I want ports 3 - 24 only able to talk too ports 1 and 2. Say port 5 receives some broadcast traffic I want it to only show up on ports 1 and 2.

Is there a simple way to do this with the switch features on the CRS?

You may find what you’re looking for here
https://wiki.mikrotik.com/wiki/Manual:CRS_examples

Far down that page there’s an example called “isolation”