PPPOE Firewall setup

Hello, first time user of RouterBoard products. A customer of mine swears by them, so when I was having DSL bandwidth accounting issues, I went with RouterOS! I just installed an RB2011UAS in my network. My internet connection is ADSL+PPPOE, so right out of the box I had my hands full, as the unit is not setup to do PPPOE. I got it up and running. I had to move the gateway port to port 10, as port 1 was having auto negotiation issues with the 100mbit ADSL modem interface. I got the PPPOE client connected on eth10, and removed eth10 from the bridge, and added eth1 to the bridge. The problem is the unit is now wide open to the internet. I know I have missed moving something to either eth10 or pppoe, maybe dnat, or something , but running a port scan on the unit from the internet shows all the ports that should only be open on the lan as wide open. WHat have I missed getting the router secure again? All the iptables rules are there, but seem to not be associated with any interfaces.