Cap RouterOS ugrading behind Hotspot

Hello,

I have set up hostspot and capsman on a vlan. The CapXLs cannot upgrade because of the hostspot blocking their requests.
How can I solve that ?

Also, all clients can access CapXLs using webfig or winbox. They can olso connect to each other. What is the proper way to prevent that ?
Is there some sort of client isolation available ?

I walledgardened a few urls, still cannot upgrade :


 /ip hotspot walled-garden print
Columns: SERVER, DST-HOST, ACTION, HITS
# SERVER  DST-HOST                ACTION  HITS
0 public  ^upgrade.mikrotik.com   allow      0
1 public  ^mikrotik.com           allow      0
2 public  ^download.mikrotik.com  allow      0

Capture d’écran du 2023-01-06 13-59-43.png

I removed the ^ and it works, it seems like regexp aren’t supported.