It shouldn’t be your responsibility to protect your customers routers. If they decide to open management to the Internet, that is highly inadvisable, but as an ISP we do not block that.
Customer radios with terminated PPPoE, as long as they are managed by you, can be set to prevent management on the PPPoE interface and only allow management via the management VLAN. We do this in cases where we have Ubiquiti subscriber units terminating PPPoE.
- I was adcived by mikrotik support to have PPPoE AC without connection tracking, firewall and NAT: Everything is due to problem i cannot go over 1.4k users on single one AC: > http://forum.mikrotik.com/t/pppoe-server-on-ccr1036-getting-to-1-5k-users-no-ip-in-addresses-no-route/144436/1
You don’t need connection tracking or NAT. You can try adding a few forward chain firewall rules with both connection tracking and NAT turned off and see how it impacts performance.