Clients behind hotspot cant reach internet?

I have an RB962 as router/firewall/dhcp with incoming fibre on SFP. To this i have a wAP ac acting as an AP for wireless. CAPsMAN is configured properly on the RB962 and works as expected.

Now i try to setup an additinal SSID with Hotspot activted to be able to direct some user to the Hotspot wifi instead to limit their uptime etc. I have done as following:

Created an aditional bridge named “hotspot”, added a 2nd config, datapath, security to CAPsMAN and added slave config to the provisioning. This works and new caps interfaces are created and i have both SSID, for “standard” wifi and hotspot.

Then i added a new subnet 192.168.89.1/24 (running on default 192.168.88.1/24) and assigned this to the hotspot bride. I also did add a new dhcp server for the hotspot bridge with a new ip pool. Lastly i did run the hotspot wizard to set that up.

When i connect to the hotspot SSID i can login and after successfull login i can see the client under Active. On the client under network information i have an ip assigned, correct gateway (192.168.89.1) and correct DNS (192.168.89.1 and DNS from ISP).

However.. the clients cant get anywhere on internet! What do i do wrong!?

EDIT: No gurus in here? Cant reallt understand why its not working…