Here is the configuration on the switch:
# jun/06/2022 11:12:20 by RouterOS 6.49.6
# software id = GR27-EFYX
#
# model = CRS328-24P-4S+
/interface bridge
add dhcp-snooping=yes igmp-snooping=yes ingress-filtering=yes name=bridge vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] loop-protect=on poe-out=off
set [ find default-name=ether2 ] loop-protect=on poe-out=off
set [ find default-name=ether3 ] loop-protect=on poe-out=off
set [ find default-name=ether4 ] loop-protect=on poe-out=off
set [ find default-name=ether5 ] loop-protect=on poe-out=off
set [ find default-name=ether6 ] loop-protect=on
set [ find default-name=ether7 ] loop-protect=on poe-out=off
set [ find default-name=ether8 ] loop-protect=on poe-out=off
set [ find default-name=ether9 ] loop-protect=on poe-out=off
set [ find default-name=ether10 ] loop-protect=on poe-out=off
set [ find default-name=ether11 ] loop-protect=on poe-out=off
set [ find default-name=ether12 ] loop-protect=on poe-out=off
set [ find default-name=ether13 ] loop-protect=on poe-out=off
set [ find default-name=ether14 ] loop-protect=on poe-out=off
set [ find default-name=ether15 ] loop-protect=on poe-out=off
set [ find default-name=ether16 ] loop-protect=on poe-out=off
set [ find default-name=ether17 ] loop-protect=on poe-out=off
set [ find default-name=ether18 ] loop-protect=on poe-out=off
set [ find default-name=ether19 ] loop-protect=on poe-out=off
set [ find default-name=ether20 ] loop-protect=on poe-out=off
set [ find default-name=ether21 ] loop-protect=on poe-out=off
set [ find default-name=ether22 ] loop-protect=on poe-out=off
set [ find default-name=ether23 ] loop-protect=on poe-out=off
set [ find default-name=ether24 ] loop-protect=on poe-out=off
set [ find default-name=sfp-sfpplus1 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full,10000M-full loop-protect=on
set [ find default-name=sfp-sfpplus2 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full,10000M-full loop-protect=on
set [ find default-name=sfp-sfpplus3 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full,10000M-full loop-protect=on
set [ find default-name=sfp-sfpplus4 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full,10000M-full loop-protect=on
/interface vlan
add interface=bridge name=acc vlan-id=9
add interface=bridge name=default vlan-id=1
add interface=bridge name=voip vlan-id=11
/interface bonding
add mode=802.3ad name=bonding23-24 slaves=ether23,ether24 transmit-hash-policy=layer-2-and-3
/interface bridge port
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether1 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether2 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether3 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether4 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether5 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether6 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether7 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether8 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether9 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether10 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether11 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether12 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether13 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether14 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether15 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether16 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether17 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether18 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether19 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether20 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether21 pvid=9 restricted-role=yes restricted-tcn=yes
add bpdu-guard=yes bridge=bridge frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether22 pvid=9 restricted-role=yes restricted-tcn=yes
add bridge=bridge disabled=yes edge=yes-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=ether23 trusted=yes
add bridge=bridge disabled=yes edge=yes-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=ether24 trusted=yes
add bridge=bridge edge=no-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=sfp-sfpplus1 trusted=yes
add bridge=bridge edge=no-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=sfp-sfpplus2 trusted=yes
add bridge=bridge edge=no-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=sfp-sfpplus3 trusted=yes
add bridge=bridge edge=no-discover frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=sfp-sfpplus4 trusted=yes
add bridge=bridge frame-types=admit-only-vlan-tagged ingress-filtering=yes interface=bonding23-24 trusted=yes
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface bridge vlan
add bridge=bridge tagged=bridge,bonding23-24,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=1
add bridge=bridge tagged=bridge,bonding23-24,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=9
add bridge=bridge tagged="bridge,bonding23-24,sfp-sfpplus1,sfp-sfpplus2,sfp-sfpplus3,sfp-sfpplus4,ether2" untagged=ether7 vlan-ids=11
/interface ethernet switch rule
add new-vlan-id=11 ports=ether7 src-mac-address=AA:AA:AA:AA:AA:AA/FF:FF:FF:FF:FF:FF switch=switch1
/ip accounting
set enabled=yes
/ip address
add address=10.X.X.X/16 interface=voip network=10.X.0.0
/ip firewall filter
add action=drop chain=input connection-state=invalid,untracked
add action=accept chain=input connection-state=established,related
add action=accept chain=input in-interface=voip
add action=drop chain=input
add action=drop chain=forward connection-state=invalid,untracked
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward
/ip route
add distance=1 gateway=10.X.X.X
