One reason why no one responds may be that a lot of information is missing in what you wrote so far.
I assume that each "service" provides an L2-transparent "pipe" between the two sites. Do you want to dedicate each "service" to an independent group of VLANs, or do you plan some redundancy (some VLANs to prefer one of the "services" but use another if the preferred one becomes unavailable)?
Also, you mention the two ports at the right CRS to be isolated, but you didn't say whether the one for the 1 Gbit/s service is isolated too. If it is not, there is no surprise you get a loop.
When testing the VLAN filtering on a software bridge (i.e. not the CRS3xx product line), I've seen that it actually only worked in one direction (I don't remember whether it was ingress or egress), so it wasn't enough to be set at just one end of the connection. It may be the same case with the CRS 3xx, I can't say, I have never practically tested that.
It is also not clear why you cannot set port isolation (and vlan filtering) at both CRS3xx.
Instead of writing novels, post /export hide-sensitive. Use find&replace in your favourite text editor to systematically replace all occurrences of each public IP address potentially identifying you by a distinctive pattern such as my.public.ip.1.