Bridge's, VLAN's and DHCP

Hello there. This is a operational scenario, i only need to know if anyone can help me to optimize it:
Thaks!

RB3011UiAS-RM:

eth1 - eth2 = wan
eth3 - eth9 = access ports 
eth10 = trunk (poe out)
dhcp servers runing on Bridges (for each vlan)

RB962UiGS-5HacT2HnT

eth1 = trunk (poe in)
eth2 - eth5 = access ports 
wlan1 - wlan2 = access port

i need to know if it is the best configuration or if can be optimized

RB3011UiAS-RM Configuration:

# sep/24/2017 15:20:47 by RouterOS 6.38.7
/interface bridge
add name=bridge_vlan-10-admin
add name=bridge_vlan-20-servers
add name=bridge_vlan-30-testing
add name=bridge_vlan-40-cctv
add name=bridge_vlan-50-lan
add name=bridge_vlan-60-executive
add name=bridge_vlan-70-guests
/interface ethernet
set [ find default-name=sfp1 ] disabled=yes
/ip neighbor discovery
set ether1 discover=no
set ether2 discover=no
set ether3 discover=no
set ether4 discover=no
set ether5 discover=no
set ether6 discover=no
set ether7 discover=no
set ether8 discover=no
set ether9 discover=no
set ether10 discover=no
set sfp1 discover=no
set bridge_vlan-20-servers discover=no
set bridge_vlan-30-testing discover=no
set bridge_vlan-40-cctv discover=no
set bridge_vlan-50-lan discover=no
set bridge_vlan-70-guests discover=no
/interface vlan
add interface=ether10 name=ether10_vlan-10-admin vlan-id=10
add interface=ether10 name=ether10_vlan-20-servers vlan-id=20
add interface=ether10 name=ether10_vlan-30-testing vlan-id=30
add interface=ether10 name=ether10_vlan-40-cctv vlan-id=40
add interface=ether10 name=ether10_vlan-50-lan vlan-id=50
add interface=ether10 name=ether10_vlan-60-executive vlan-id=60
add interface=ether10 name=ether10_vlan-70-guests vlan-id=70
/ip neighbor discovery
set ether10_vlan-10-admin discover=no
set ether10_vlan-20-servers discover=no
set ether10_vlan-30-testing discover=no
set ether10_vlan-40-cctv discover=no
set ether10_vlan-50-lan discover=no
set ether10_vlan-60-executive discover=no
set ether10_vlan-70-guests discover=no
/interface list
add name=wan
add name=lan
/ip pool
add name=pool-vlan-10 ranges=172.16.10.100-172.16.10.200
add name=pool-vlan-20 ranges=172.16.20.100-172.16.20.200
add name=pool-vlan-30 ranges=172.16.30.100-172.16.30.200
add name=pool-vlan-40 ranges=172.16.40.100-172.16.40.200
add name=pool-vlan-50 ranges=172.16.50.100-172.16.50.200
add name=pool-vlan-60 ranges=172.16.60.100-172.16.60.200
add name=pool-vlan-70 ranges=172.16.70.100-172.16.70.200
/ip dhcp-server
add address-pool=pool-vlan-10 disabled=no interface=bridge_vlan-10-admin \
    lease-time=1w name=dhcp_vlan-10
add address-pool=pool-vlan-20 disabled=no interface=bridge_vlan-20-servers \
    lease-time=1w name=dhcp_vlan-20
add address-pool=pool-vlan-30 disabled=no interface=bridge_vlan-30-testing \
    lease-time=1w name=dhcp_vlan-30
add address-pool=pool-vlan-40 disabled=no interface=bridge_vlan-40-cctv \
    lease-time=1w name=dhcp_vlan-40
add address-pool=pool-vlan-50 disabled=no interface=bridge_vlan-50-lan \
    lease-time=1w name=dhcp_vlan-50
add address-pool=pool-vlan-60 disabled=no interface=bridge_vlan-60-executive \
    lease-time=1w name=dhcp_vlan-60
add address-pool=pool-vlan-70 disabled=no interface=bridge_vlan-70-guests \
    lease-time=1w name=dhcp_vlan-70
/interface bridge port
add bridge=bridge_vlan-10-admin interface=ether3
add bridge=bridge_vlan-60-executive interface=ether9
add bridge=bridge_vlan-50-lan interface=ether5
add bridge=bridge_vlan-50-lan interface=ether6
add bridge=bridge_vlan-50-lan interface=ether7
add bridge=bridge_vlan-50-lan interface=ether8
add bridge=bridge_vlan-10-admin interface=ether10_vlan-10-admin
add bridge=bridge_vlan-20-servers interface=ether10_vlan-20-servers
add bridge=bridge_vlan-30-testing interface=ether10_vlan-30-testing
add bridge=bridge_vlan-40-cctv interface=ether10_vlan-40-cctv
add bridge=bridge_vlan-50-lan interface=ether10_vlan-50-lan
add bridge=bridge_vlan-60-executive interface=ether10_vlan-60-executive
add bridge=bridge_vlan-70-guests interface=ether10_vlan-70-guests
/ip address
add address=172.16.10.1/24 interface=bridge_vlan-10-admin network=172.16.10.0
add address=172.16.20.1/24 interface=bridge_vlan-20-servers network=\
    172.16.20.0
add address=172.16.30.1/24 interface=bridge_vlan-30-testing network=\
    172.16.30.0
add address=172.16.40.1/24 interface=bridge_vlan-40-cctv network=172.16.40.0
add address=172.16.50.1/24 interface=bridge_vlan-50-lan network=172.16.50.0
add address=172.16.60.1/24 interface=bridge_vlan-60-executive network=\
    172.16.60.0
add address=172.16.70.1/24 interface=bridge_vlan-70-guests network=\
    172.16.70.0
/ip dhcp-client
add default-route-distance=0 dhcp-options=hostname,clientid disabled=no \
    interface=ether1
/ip dhcp-server lease
add address=172.16.60.86 client-id=1:e4:a7:a0:23:17:34 mac-address=\
    E4:A7:A0:23:17:34 server=dhcp_vlan-60
add address=172.16.10.86 client-id=1:c8:5b:76:65:18:7e mac-address=\
    C8:5B:76:65:18:7E server=dhcp_vlan-10
/ip dhcp-server network
add address=172.16.10.0/24 dns-server=172.16.10.1 gateway=172.16.10.1 \
    netmask=24
add address=172.16.20.0/24 dns-server=172.16.20.1 gateway=172.16.20.1 \
    netmask=24
add address=172.16.30.0/24 dns-server=172.16.30.1 gateway=172.16.30.1 \
    netmask=24
add address=172.16.40.0/24 dns-server=172.16.40.1 gateway=172.16.40.1 \
    netmask=24
add address=172.16.50.0/24 dns-server=172.16.50.1 gateway=172.16.50.1 \
    netmask=24
add address=172.16.60.0/24 dns-server=172.16.60.1 gateway=172.16.60.1 \
    netmask=24
add address=172.16.70.0/24 dns-server=172.16.70.1 gateway=172.16.70.1 \
    netmask=24
/ip dns
set allow-remote-requests=yes cache-size=4096KiB
/ip firewall nat
add action=masquerade chain=srcnat comment=masquerade out-interface=ether1
add action=masquerade chain=srcnat out-interface=ether2

RB962UiGS-5HacT2HnT Configuration:

# sep/24/2017 15:21:38 by RouterOS 6.38.7
#
/interface bridge
add name=bridge_vlan-10-admin
add name=bridge_vlan-20-servers
add name=bridge_vlan-30-testing
add name=bridge_vlan-40-cctv
add name=bridge_vlan-50-lan
add name=bridge_vlan-60-executive
add name=bridge_vlan-70-guests
/interface ethernet
set [ find default-name=sfp1 ] disabled=yes
/ip neighbor discovery
set ether1 discover=no
set ether2 discover=no
set ether3 discover=no
set ether4 discover=no
set ether5 discover=no
set sfp1 discover=no
set bridge_vlan-20-servers discover=no
set bridge_vlan-30-testing discover=no
set bridge_vlan-40-cctv discover=no
set bridge_vlan-50-lan discover=no
set bridge_vlan-70-guests discover=no
/interface vlan
add interface=ether1 name=ether1_vlan-10-admin vlan-id=10
add interface=ether1 name=ether1_vlan-20-servers vlan-id=20
add interface=ether1 name=ether1_vlan-30-testing vlan-id=30
add interface=ether1 name=ether1_vlan-40-cctv vlan-id=40
add interface=ether1 name=ether1_vlan-50-lan vlan-id=50
add interface=ether1 name=ether1_vlan-60-executive vlan-id=60
add interface=ether1 name=ether1_vlan-70-guests vlan-id=70
/ip neighbor discovery
set ether1_vlan-10-admin discover=no
set ether1_vlan-20-servers discover=no
set ether1_vlan-30-testing discover=no
set ether1_vlan-40-cctv discover=no
set ether1_vlan-50-lan discover=no
set ether1_vlan-60-executive discover=no
set ether1_vlan-70-guests discover=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk eap-methods="" management-protection=\
    allowed mode=dynamic-keys name=gilad0-lan supplicant-identity="" \
    wpa2-pre-shared-key=asdasdasdasd#
add authentication-types=wpa2-psk eap-methods="" management-protection=\
    allowed mode=dynamic-keys name=gilad0-executive supplicant-identity="" \
    wpa2-pre-shared-key="asdasdasdasd"
add authentication-types=wpa2-psk eap-methods="" management-protection=\
    allowed mode=dynamic-keys name=gilad0-guests supplicant-identity="" \
    wpa2-pre-shared-key=asdasdasdasd
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-g/n bridge-mode=disabled disabled=\
    no frequency=auto hide-ssid=yes mode=ap-bridge name=\
    wlan1_vlan-60-executive security-profile=gilad0-executive ssid=\
    gilad0-executive wireless-protocol=802.11 wps-mode=disabled
add disabled=no keepalive-frames=disabled mac-address=6E:3B:6B:BD:AE:0E \
    master-interface=wlan1_vlan-60-executive mode=ap-bridge \
    multicast-buffering=disabled name=wlan1_vlan-70-guests security-profile=\
    gilad0-guests ssid=gilad0-invitados wds-cost-range=0 wds-default-cost=0 \
    wps-mode=disabled
set [ find default-name=wlan2 ] band=5ghz-onlyac bridge-mode=disabled \
    disabled=no frequency=auto hide-ssid=yes mode=ap-bridge name=\
    wlan2_vlan60-executive-5ghz security-profile=gilad0-executive ssid=\
    gilad0-executive wireless-protocol=802.11 wps-mode=disabled
/ip neighbor discovery
set wlan1_vlan-70-guests discover=no
/interface wireless
add disabled=no hide-ssid=yes keepalive-frames=disabled mac-address=\
    6E:3B:6B:BD:AE:0D master-interface=wlan1_vlan-60-executive mode=ap-bridge \
    multicast-buffering=disabled name=wlan1_vlan-50-lan security-profile=\
    gilad0-lan ssid=gilad0-lan wds-cost-range=0 wds-default-cost=0 wps-mode=\
    disabled
add disabled=no hide-ssid=yes keepalive-frames=disabled mac-address=\
    6E:3B:6B:BD:AE:0C master-interface=wlan2_vlan60-executive-5ghz mode=\
    ap-bridge multicast-buffering=disabled name=wlan2_vlan-50-lan-5ghz \
    security-profile=gilad0-lan ssid=gilad0-lan wds-cost-range=0 \
    wds-default-cost=0 wps-mode=disabled
add disabled=no keepalive-frames=disabled mac-address=6E:3B:6B:BD:AE:0E \
    master-interface=wlan2_vlan60-executive-5ghz mode=ap-bridge \
    multicast-buffering=disabled name=wlan2_vlan-70-guests-5ghz \
    security-profile=gilad0-guests ssid=gilad0-invitados wds-cost-range=0 \
    wds-default-cost=0 wps-mode=disabled
/ip neighbor discovery
set wlan1_vlan-50-lan discover=no
set wlan2_vlan-50-lan-5ghz discover=no
set wlan2_vlan-70-guests-5ghz discover=no
/interface bridge port
add bridge=bridge_vlan-10-admin interface=ether1_vlan-10-admin
add bridge=bridge_vlan-20-servers interface=ether1_vlan-20-servers
add bridge=bridge_vlan-30-testing interface=ether1_vlan-30-testing
add bridge=bridge_vlan-40-cctv interface=ether1_vlan-40-cctv
add bridge=bridge_vlan-50-lan interface=ether1_vlan-50-lan
add bridge=bridge_vlan-60-executive interface=ether1_vlan-60-executive
add bridge=bridge_vlan-70-guests interface=ether1_vlan-70-guests
add bridge=bridge_vlan-60-executive interface=wlan1_vlan-60-executive
add bridge=bridge_vlan-50-lan interface=wlan1_vlan-50-lan
add bridge=bridge_vlan-50-lan interface=wlan2_vlan-50-lan-5ghz
add bridge=bridge_vlan-60-executive interface=wlan2_vlan60-executive-5ghz
add bridge=bridge_vlan-10-admin interface=ether3
add bridge=bridge_vlan-10-admin interface=ether2
add bridge=bridge_vlan-60-executive interface=ether4
add bridge=bridge_vlan-60-executive interface=ether5
add bridge=bridge_vlan-70-guests interface=wlan1_vlan-70-guests
add bridge=bridge_vlan-70-guests interface=wlan2_vlan-70-guests-5ghz
/ip address
add address=172.16.10.2/24 interface=bridge_vlan-10-admin network=172.16.10.0
add address=172.16.20.2/24 interface=bridge_vlan-20-servers network=\
    172.16.20.0
add address=172.16.30.2/24 interface=bridge_vlan-30-testing network=\
    172.16.30.0
add address=172.16.40.2/24 interface=bridge_vlan-40-cctv network=172.16.40.0
add address=172.16.50.2/24 interface=bridge_vlan-50-lan network=172.16.50.0
add address=172.16.60.2/24 interface=bridge_vlan-60-executive network=\
    172.16.60.0
add address=172.16.70.2/24 interface=bridge_vlan-70-guests network=\
    172.16.70.0
/ip dns
set servers=10.0.40.1
/ip route
add distance=1 gateway=172.16.10.1
/ip service
set telnet address=172.16.60.0/24,172.16.60.0/24 disabled=yes
set ftp address=172.16.60.0/24,172.16.60.0/24 disabled=yes
set www address=172.16.60.0/24,172.16.60.0/24 disabled=yes
set ssh address=172.16.60.0/24,172.16.60.0/24
set www-ssl address=172.16.60.0/24,172.16.60.0/24
set api address=172.16.60.0/24,172.16.60.0/24 disabled=yes
set winbox address=172.16.10.0/24,172.16.60.0/24
set api-ssl address=172.16.60.0/24,172.16.60.0/24 disabled=yes
/system identity
set name=rb-ap
/system package update
set channel=bugfix
/tool user-manager database
set db-path=flash/user-manager