Admin VLAN - will bridging have problems?

I start having a number of Mikrotik devices in different places. Need to secure them.

For this I think of putting up a VLAN (using VPLS) for them, with every router having one specific IP. This would run into a central location where it would be bridged with all of them as well as one vlan port that goes out to an admin port or two.

Anyone sees any problems with that? How do you handle limiting access to routers;)? A simple firewall filter seems quite limiting to me. I would love to totally hide the admin vlan.