I have a CRS312-4C+8XG (both OS and firmware are running 7.1.3) acting as a basic NAT router with ether1 port as WAN port and rest of ports as internal LAN. I also configured fast-track on established and related traffic. Internal LAN traffic can NAT out to outside networks successfully.
Some devices have two switch chips or the management port directly connected to the CPU.
For example, > CRS312-4C+8XG > has an ether9 port connected to a separate switch chip.
Trying to add this port to a bridge or involve it in the L3HW setup leads to unexpected results. Leave the management port for management!