Hello,
i only will allow PPPoE from ports on CRS317 to uplink-port. no access to switch from customer-ports, nothing. only PPPoE...
I have set these rules:
/interface ethernet switch rule
add disabled=yes mac-protocol=pppoe-discovery new-dst-ports=sfp-sfpplus1-uplink ports=sfp-sfpplus2-205162,sfp-sfpplus3-202669,sfp-sfpplus4-202490,sfp-sfpplus5-201434,sfp-sfpplus6-ebert-hs8a,sfp-sfpplus7-200452,sfp-sfpplus8-206799 switch=switch1
add disabled=yes mac-protocol=pppoe new-dst-ports=sfp-sfpplus1-uplink ports=sfp-sfpplus2-205162,sfp-sfpplus3-202669,sfp-sfpplus4-202490,sfp-sfpplus5-201434,sfp-sfpplus6-ebert-hs8a,sfp-sfpplus7-200452,sfp-sfpplus8-206799 switch=switch1
add disabled=yes new-dst-ports=sfp-sfpplus16-blackhole ports=sfp-sfpplus2-205162,sfp-sfpplus3-202669,sfp-sfpplus4-202490,sfp-sfpplus5-201434,sfp-sfpplus6-ebert-hs8a,sfp-sfpplus7-200452,sfp-sfpplus8-206799 switch=switch1
o.k. Work.only PPPoE is allowed. But when i activated, then the Bridge learns no mac from the ports. So the Bridge sends out the incomming traffic to all ports?!
Must i set
copy-to-cpu (no | yes; Default: no)
Is this not CPU overloading?
thank you
Christian