if I do the /24 do I still do
CODE: SELECT ALL
add address=2.2.2.1 interface=vlan10 network=2.2.2.10
or would I do
CODE: SELECT ALL
add address=2.2.2.1/24 interface=vlan10 network=2.2.2.0
The first one.
Also - you'd want to enable arp=proxy-arp on the customer-vlan interfaces so that the customers can reach each other. (they may want to do vpn with each other, or whatever one might use a public IP address for) - and the customer can configure their device with /24 and everything will work perfectly.
Oh - and one final tip - you'll want to black-hole the entire /24 by default:
/ip route add dst=2.2.2.0/24 type=blackhole
Using the "network=2.2.2.X" on a customer interface will create a connected /32 route for that customer, which will be more specific than the black hole route. The reason you want to black hole the /24 is so that un-allocated addresses' traffic gets thrown in the trash. Otherwise, whenever a zombie bot is scanning your network, the scan packets for unused addresses would ping-pong between your router and the ISP's router until the TTL expires.