Here is my answer in another thread that can also be applied to your setup http://forum.mikrotik.com/t/routing-transparent-vlan/184051/1
Of course, you can have more ports in your VLAN aware bridge, not just ether1 and ether2 like that thread. You can distribute that “VLAN2000” to other ports as you wish, tagged or untagged, same with the IPTV VLAN. And your equivalence to “VLAN1000” is probably tagged on the WAN port instead of untagged.
But the general, the idea is still the same: make your WAN port menber of the same VLAN-enabled bridge as your LAN ports. The VLAN that you use to dial PPPoE only has the WAN port and the bridge port as member, so on Layer 2 it’s properly isolated from the rest your LAN. The IPTV VLAN is bridged and can take advantage of hardware offload if your device supports that.