Client protection for Hotspot with several APs

I have attached a simplified network diagram. I am looking to create a “Guest” network and a “MGMT” network on these APs. There are many more but this version will cover most bases. I can’t decide if I want to VLAN or just Virtual AP for best approach. There is a house connection not shown here which should be on the protected management network as well. I would like to be able to use the Office PC to control all mikrotik devices on the network and it should also reside on the MGMT network. Simple Firewall rules did not work for me since there are VOIP devices spread throughout.

Thanks for your assistance!
network.jpg

For now, I ended up using CapsMan to bring all forwarding to main router and utilize a HotSpot Bridge for all public connections utilizing a different subnet and added appropriate firewall entries.