Hi there!
Thanks for your swift response. Sure, its using the cpu, thats obvious. Not sure why though.
Here is the output of /interface export:
/interface bridge
add name=bridge1 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] l2mtu=1592 name=ether1
set [ find default-name=sfp-sfpplus1 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus1
set [ find default-name=sfp-sfpplus2 ] disabled=yes l2mtu=1592 mtu=1592
set [ find default-name=sfp-sfpplus3 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus3
set [ find default-name=sfp-sfpplus4 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus4
set [ find default-name=sfp-sfpplus5 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus5
set [ find default-name=sfp-sfpplus6 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus6
set [ find default-name=sfp-sfpplus7 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus7
set [ find default-name=sfp-sfpplus8 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus8
set [ find default-name=sfp-sfpplus9 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus9
set [ find default-name=sfp-sfpplus10 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus10
set [ find default-name=sfp-sfpplus11 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus11
set [ find default-name=sfp-sfpplus12 ] disabled=yes l2mtu=1592 mtu=1592
set [ find default-name=sfp-sfpplus13 ] disabled=yes l2mtu=1592 mtu=1592
set [ find default-name=sfp-sfpplus14 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus14
set [ find default-name=sfp-sfpplus15 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus15
set [ find default-name=sfp-sfpplus16 ] l2mtu=1592 mtu=1592 name=sfp-sfpplus16
/interface vlan
add interface=bridge1 name=vlan1 vlan-id=1
add interface=bridge1 name=vlan2 vlan-id=2
add interface=bridge1 name=vlan100 vlan-id=100
add interface=bridge1 name=vlan101 vlan-id=101
add interface=bridge1 name=vlan251 vlan-id=251
add interface=bridge1 name=vlan254 vlan-id=254
/interface bonding
add mode=802.3ad name=LACP slaves=sfp-sfpplus15,sfp-sfpplus16
/interface ethernet switch
set 0 l3-hw-offloading=yes
/interface lte apn
set [ find default=yes ] ip-type=ipv4
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge1 interface=sfp-sfpplus1
add bridge=bridge1 interface=sfp-sfpplus2
add bridge=bridge1 interface=sfp-sfpplus3
add bridge=bridge1 interface=sfp-sfpplus4
add bridge=bridge1 interface=sfp-sfpplus5
add bridge=bridge1 interface=sfp-sfpplus6
add bridge=bridge1 interface=sfp-sfpplus7
add bridge=bridge1 interface=sfp-sfpplus8
add bridge=bridge1 interface=sfp-sfpplus9
add bridge=bridge1 interface=sfp-sfpplus10 pvid=133
add bridge=bridge1 interface=sfp-sfpplus11
add bridge=bridge1 interface=sfp-sfpplus12
add bridge=bridge1 interface=sfp-sfpplus13
add bridge=bridge1 interface=sfp-sfpplus14
add bridge=bridge1 interface=LACP
/interface bridge vlan
add bridge=bridge1 tagged=LACP,sfp-sfpplus14 vlan-ids=10
add bridge=bridge1 tagged=sfp-sfpplus1,sfp-sfpplus14,sfp-sfpplus11 vlan-ids=133
add bridge=bridge1 tagged=bridge1 untagged=sfp-sfpplus1,sfp-sfpplus14,vlan1 vlan-ids=1
add bridge=bridge1 tagged="LACP,sfp-sfpplus14,sfp-sfpplus1,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,s\
fp-sfpplus3,sfp-sfpplus4,bridge1" vlan-ids=251
add bridge=bridge1 tagged=LACP,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=66
add bridge=bridge1 tagged=sfp-sfpplus14,sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=\
13
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus9,sfp-sfpplus3,sfp-sfpplus4,bridge1 \
vlan-ids=2
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus14,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=\
117
add bridge=bridge1 tagged="sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus14,sfp-sfpplus9,sfp-sfpplus11,s\
fp-sfpplus3,sfp-sfpplus4,bridge1" vlan-ids=100
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus3,sfp-sfpplus4,bridge1 vlan-ids=101
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus3,sfp-sfpplus4 vlan-ids=102
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus3,sfp-sfpplus4,bridge1 vlan-ids=254
and the output of "/ip export":
/ip address
add address=10.0.2.254/24 interface=vlan2 network=10.0.2.0
add address=10.0.1.254/24 interface=vlan1 network=10.0.1.0
add address=10.0.100.254/24 interface=vlan100 network=10.0.100.0
add address=10.0.101.254/24 interface=vlan101 network=10.0.101.0
add address=10.0.254.254/24 interface=vlan254 network=10.0.254.0
add address=10.0.232.254/24 interface=vlan251 network=10.0.232.0
/ip dhcp-relay
add dhcp-server=10.0.2.30 disabled=no interface=vlan1 local-address=10.0.1.254 name=ip-helper-vlan1
add dhcp-server=10.0.2.30 disabled=no interface=vlan100 name=ip-helper-vlan100
add dhcp-server=10.0.2.30 disabled=no interface=vlan101 name=ip-helper-vlan101
/ip dns
set servers=10.0.2.30,10.0.2.40
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set rp-filter=strict tcp-syncookies=yes
/ip firewall filter
add action=reject chain=forward out-interface=vlan251 reject-with=icmp-admin-prohibited
add action=reject chain=forward in-interface=vlan251 reject-with=icmp-admin-prohibited
add action=fasttrack-connection chain=forward connection-state=established,related,untracked hw-offload=yes
add action=accept chain=forward connection-state=established,related,untracked
add action=reject chain=input disabled=yes reject-with=icmp-admin-prohibited src-address=!10.0.232.0/24
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=10.0.254.1
/ip service
set telnet address=10.0.232.0/24 disabled=yes
set ftp address=10.0.232.0/24
set www address=10.0.232.0/24
set ssh address=10.0.232.0/24
set www-ssl address=10.0.232.0/24
set api address=10.0.232.0/24
set winbox address=10.0.232.0/24
set api-ssl address=10.0.232.0/24
/ip traffic-flow
set enabled=yes
/ip traffic-flow target
add dst-address=10.0.232.16 port=4739 src-address=10.0.232.254 version=ipfix
Please note: There is another bug i discovered while testing.
Its with the "export" command: Some settings have a trailing and ending ". This prevents one to quickly import the config previously exported.
One has to remove those ". Example:
This one would not work:
/interface bridge vlan
add bridge=bridge1 tagged="sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus14,sfp-sfpplus9,sfp-sfpplus11,s\
fp-sfpplus3,sfp-sfpplus4,bridge1" vlan-ids=100
This one would work:
/interface bridge vlan
add bridge=bridge1 tagged=sfp-sfpplus5,sfp-sfpplus6,sfp-sfpplus7,sfp-sfpplus8,sfp-sfpplus14,sfp-sfpplus9,sfp-sfpplus11,s\
fp-sfpplus3,sfp-sfpplus4,bridge1 vlan-ids=100
Thanks for your help!
Kind regards