The expected behavior all depends on how you did the configuration and without seeing this makes it impossible to comment.
I do suspect that you stopped halfway, if you read further in the quoted URL, you will see where it talks about "Unintentionally allowed management access..." And explains how to correct this
Did read the section but may miss a point. Reduced the config to the bridge/vlan part:
/system identity set name=gwleak
/interface bridge
add ingress-filtering=yes name=bridge1 vlan-filtering=yes
/interface vlan
add interface=bridge1 name=vlan1 vlan-id=1
add interface=bridge1 name=vlan2 vlan-id=2
add interface=bridge1 name=vlan4 vlan-id=4
add interface=bridge1 name=vlan11 vlan-id=11
/interface bridge port
add bridge=bridge1 ingress-filtering=yes interface=ether2
add bridge=bridge1 frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether3 pvid=2
add bridge=bridge1 frame-types=admit-only-untagged-and-priority-tagged ingress-filtering=yes interface=ether4 pvid=2
/interface bridge vlan
add bridge=bridge1 tagged=bridge1 untagged=ether2 vlan-ids=1
add bridge=bridge1 tagged=ether2,bridge1 untagged=vplsTunnelXXX vlan-ids=4
add bridge=bridge1 tagged=ether2,bridge1 vlan-ids=11
add bridge=bridge1 tagged=bridge1 untagged=ether3,ether4 vlan-ids=2
/ip address
add address=192.168.50.201/28 interface=vlan11 network=192.168.50.192
add address=213.185.129.178/29 interface=vlan11 network=213.185.129.176
add address=192.168.52.209/28 interface=vlan1 network=192.168.52.208
This is neighbor discovery from another MT box reachable via ether3. 48:8F:5A:11:F1:C2 is MAC of ether3, 48:8F:5A:11:F1:C1 is MAC of ether2/bridge interface.
1 interface=ether2,bridge-local mac-address=48:8F:5A:11:F1:C2 identity=gwleak platform=MikroTik version=6.47 (stable) unpack=none age=35s interface-name=bridge1/ether3 system-descript
ion=MikroTik RouterOS 6.47 (stable) RB450Gx4 system-caps=bridge,router system-caps-enabled=bridge,router
2 interface=ether2,bridge-local address=192.168.180.19 address4=192.168.180.19 mac-address=48:8F:5A:11:F1:C1 identity=gwleak platform=MikroTik version=6.47 (stable) unpack=none age=35
s uptime=7m18s software-id=NK1R-I2VX board=RB450Gx4 ipv6=no interface-name=vlan2 system-description=MikroTik RouterOS 6.47 (stable) RB450Gx4 system-caps=bridge,router system-caps-enab
led=bridge,router
I could login with winbox on both MAC Adresses.