I ‘ve got 4 x cAP AC XL and 750GR3. All these device run RouterOS 7.21 testing and APs have wifi-qcom-ac installed. My question is not about VLANs in that configuration since I see it is well covered. The problem is how to fully isolate guest wifi client between themselves without capsman forwarding. Maybe someone knows how to do that?
There is a client-isolation property in datapath. As you are using the wifi-qcom-ac driver, I think that won't do anything, as there is a single datapath in case of vlan's.
In the description it mentions "This policy can be overridden on a per-client basis using access list rules, so a an AP can have a mixture of isolated and non-isolated clients."
I have no experience with this, but it might point you in the right direction.