A modem, a hub and two mikrotik routers

Hello.

I have a network setup with a TP-Link Hub that is connected to my ISPs modem where they serve my external IP address to me via DHCP and two mikrotik hAP ac routers connected to the switch on ether1. I want Router 1 (R1) to act as a DHCP client for the ISPs modem, DHCP server for the local network, provide wifi access as well as provide NAT, while Router 2 (R2) to be part of the local network and only provide bridged wifi access. The wifi networks don’t have to share SSIDs.

I was messing around in winbox yesterday and managed to get a setup that worked but I think I exposed my network to the external world since I started seeing telnet login attempts on the admin log on R1, so I quickly killed that setup. I think I need a vlan or something. I also wonder if with this setup all traffic will have to go via R1 with this setup or will traffic from R2 be able to go directly to the internet.

Thanks for any help.

Drop the switch
Connect the ISP modem to the Primary HAPAC ROUTER.
ensure you have the basic firewall rule set in place.
(https://forum.mikrotik.com/viewtopic.php?t=180838 - see subpara 6)

Read this article.
It covers adding vlans and configuring the MAIN ROUTER as well as setting up the second AP as mainly a accesspoint/switch.
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1

Give it a whirl and then come back and post both configs
/export hide-sensitive file=anynameyouwish