Issues routing and firewall with CRS-125

Hi

Battled the whole of today on this with no resolution.
I moved a client onto a CRS-125 switch OS 6.19 and moved their PPPOE onto this and it all works great as does the VPN to our office.

I tried to move 2 wireless guest devices to ports which I took out of the master port and set them up with their own ips and DHCP.

Problem 1
They can ping ips on the internet but DNS is not resolving even though it is set to use internal and external google DNS for these wireless users.

Problem 2
They can ping and can RDP to the windows server on the main LAN even though I set a source and destination firewall drop rule. The firewall rule just does not seem to have any effect. I am guessing it is an issue because of the switch/bridge ?

I suppose I can look at isolation using vlans.

Has anyone successfully used a CRS-125 switch as both a switch and a router?

Have you set these up with a Bridge interface?

Hi

The servers and DSL bridged modem are all on the default switch/bride-local ports.

I removed 2 ports from the switch by removing the master port setting.

I suspect the problem is routing between isolated routed ports and bridged/switch ports as I have had problems in the past with routes and bridges.

Unfortunately the mikrotik solution is already in place as thinking about it the best approach would have been to leave the CRS-125 to perform as just a switch and use a RB750GL to be the router however I don’t see why the CRS-125 can’t be both.

I have not been back to try it using vlans yet.