CRS125-24G-1s VLAN problem

Hello folks,

here comes configuration

/interface ethernet
set [ find default-name=ether1 ] name=ether1-Master-Mikrotik1

...

set [ find default-name=ether24 ] master-port=ether1-Master-Mikrotik1
set [ find default-name=sfp1 ] master-port=ether1-Master-Mikrotik1
/interface vlan
add interface=ether1-Master-Mikrotik1 name=130-locals vlan-id=130
add interface=ether1-Master-Mikrotik1 name=2952 vlan-id=2952
/ip pool
add name=dhcp_pool1 ranges=192.168.1.51-192.168.1.254
/ip dhcp-server
add address-pool=dhcp_pool1 disabled=no interface=130-locals lease-time=1h \
    name=dhcp1
/ip firewall connection tracking
set enabled=yes
/interface ethernet switch egress-vlan-tag
add tagged-ports=ether1-Master-Mikrotik1,switch1-cpu vlan-id=2952
add tagged-ports=ether1-Master-Mikrotik1,switch1-cpu vlan-id=1
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2951
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2950
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2953
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2954
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2956
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2957
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2958
add tagged-ports=ether1-Master-Mikrotik1 vlan-id=2959
add tagged-ports=ether1-Master-Mikrotik1,switch1-cpu vlan-id=130
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=2952 ports=\
    ether2,ether3,ether5,ether4,ether6,ether7,ether8,ether9,ether10
add new-customer-vid=130 ports="ether11,ether12,ether13,ether14,ether15,ether1\
    6,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24" \
/interface ethernet switch vlan
add ports="ether1-Master-Mikrotik1,ether2,ether3,ether4,ether5,ether6,ether7,e\
    ther8,ether9,ether10,switch1-cpu" vlan-id=2952
add ports=ether1-Master-Mikrotik1,switch1-cpu vlan-id=1
add ports="ether1-Master-Mikrotik1,ether11,ether12,ether13,ether14,ether15,eth\
    er16,ether17,ether18,ether19,ether20,ether21,ether22,ether23,ether24,switc\
    h1-cpu" vlan-id=130
/ip address
add address=192.168.1.1/24 interface=130-locals network=192.168.1.0
add address=84.XXX.XXX.XXX/27 interface=2952 network=84.XXX.XXX.XXX
/ip dhcp-server network
add address=192.168.1.0/24 dns-server=212.7.5.250,212.7.9.34,212.7.0.33 \
    gateway=192.168.1.1
/ip firewall nat
add action=masquerade chain=srcnat out-interface=2952 src-address=\
    192.168.1.0/24
/ip route
add distance=1 gateway=84.XXX.XXX.XXX

CRS works fine as router.
But if I plug in devices in ports from 2 to 10 (vlan 2952) I can ping them from switch itself ant from switch internal net (192.168.) but I can’t ping this device from anything connected to port 1 via trunk.

Please help!

RGDS
D.