Basic setup with VLAN tagging

Currently, your router tells its DHCP clients in the LAN to use 192.168.88.1 (which is the router itself) as DNS resolver. However your IP -> DNS settings does not have "Allow Remote Requests" enabled. As a result the client devices can't resolve domain names.

Enable that checkbox. But then search for the default MikroTik firewall rules on this forum (there's a post from @rextended) and apply it.

Also disable the Use IP Firewall on the bridge setting as @Amm0 mentioned above.