hAP ac3 - Router OS 7.13 WIFI to vlan

Hi everyone,
I wonder if you could help me to set up my hAP ac3 properly. I am a newbie with Mikrotik but getting to be a fan of it. Basically, I have a hAP ac3 device, and created a bridge with to ethernet ports (ether2 and ether3). Ether1 is my uplink. I created three vlan-s. One for the lan, one for guests and one for management purposes, and set the interface of them to the bridge. Now I would like to activate wifi (wifi-qcom-ac package is installed) as well. How can I achieve if one is connected to SSID than they will be inserted into one specific VLAN? I just couldn’t figure it out on my own.
My current setting is:

/interface bridge
add name=Bridge-LAN

/interface vlan
add interface=Bridge-LAN name=vlan-10 vlan-id=10
add interface=Bridge-LAN name=vlan-20 vlan-id=20
add interface=Bridge-LAN name=vlan-99 vlan-id=99

/interface bridge port
add bridge=Bridge-LAN interface=ether2
add bridge=Bridge-LAN interface=ether3
add bridge=Bridge-LAN interface=wifi2
add bridge=Bridge-LAN interface=wifi1

/ip dhcp-server
add address-pool=POOL-LAN interface=Bridge-LAN name=DHCP-LAN
add address-pool=dhcp_pool1 interface=vlan-10 name=DHCP-VLAN-10
add address-pool=dhcp_pool2 interface=vlan-20 name=DHCP-VLAN-20

/ip address
add address=192.168.4.1/24 interface=Bridge-LAN network=192.168.4.0
add address=192.168.10.1/24 interface=vlan-10 network=192.168.10.0
add address=192.168.20.1/24 interface=vlan-20 network=192.168.20.0
add address=10.99.99.1/24 interface=vlan-99 network=10.99.99.0

Currently if I connect to wifi I will get an IP from 192.168.4.0/24 address. I would like to have an IP from 192.168.10.0/24. Is that possible with this device? Any help would be highly appreciated.

You are missing complete config here, did you untag any VLAN on any port ? I can see that VLAN filtering is not enabled.

Show us your full config minus sensitive data such as wireguard ports, public IPs, public keys for wireguard, serial of the router etc…

Time to start reading:
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1

Thanks for the answer. Yep, I missed the VLAN filtering, but not sure, where should I set it.
Here is the config:

# 2024-01-06 09:36:04 by RouterOS 7.13
# software id = 
#
# model = RBD53iG-5HacD2HnD
# serial number = xxxxxxxx
/interface bridge
add name=Bridge-LAN
/interface wireguard
add listen-port=xxxxx mtu=1420 name=wireguard1
/interface vlan
add interface=Bridge-LAN name=vlan-10 vlan-id=10
add interface=Bridge-LAN name=vlan-20 vlan-id=20
add interface=Bridge-LAN name=vlan-99 vlan-id=99
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disabled=no name=wifi1
/interface wifi configuration
add channel.band=5ghz-ac .skip-dfs-channels=10min-cac .width=20/40/80mhz \
    country=Hungary disabled=no name=wifi1-5ghz security=wifi1 ssid=wifi1
add channel.band=2ghz-n .skip-dfs-channels=10min-cac .width=20/40mhz country=\
    Hungary disabled=no name=wifi1-2ghz security=wifi1 ssid=wifi2G
/interface wifi
set [ find default-name=wifi1 ] configuration=wif1-2ghz configuration.mode=ap \
    disabled=no
set [ find default-name=wifi2 ] configuration=wif1-5ghz configuration.mode=ap \
    disabled=no
/ip pool
add name=POOL-LAN ranges=192.168.4.2-192.168.4.254
add name=dhcp_pool1 ranges=192.168.10.2-192.168.10.254
add name=dhcp_pool2 ranges=192.168.20.2-192.168.20.254
/ip dhcp-server
add address-pool=POOL-LAN interface=Bridge-LAN name=DHCP-LAN
add address-pool=dhcp_pool1 interface=vlan-10 name=DHCP-VLAN-10
add address-pool=dhcp_pool2 interface=vlan-20 name=DHCP-VLAN-20
/interface bridge port
add bridge=Bridge-LAN interface=ether2
add bridge=Bridge-LAN interface=ether3
add bridge=Bridge-LAN interface=wifi2
add bridge=Bridge-LAN interface=wifi1
/ipv6 settings
set disable-ipv6=yes
/interface wireguard peers
add allowed-address=10.70.70.2/32 client-listen-port=XXXXX comment=\
    "myphone" interface=wireguard1 persistent-keepalive=20s \
    public-key="xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
/ip address
add address=192.168.4.1/24 interface=Bridge-LAN network=192.168.4.0
add address=192.168.10.1/24 interface=vlan-10 network=192.168.10.0
add address=192.168.20.1/24 interface=vlan-20 network=192.168.20.0
add address=10.99.99.1/24 interface=vlan-99 network=10.99.99.0
add address=10.70.70.1/24 interface=wireguard1 network=10.70.70.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add interface=ether1
/ip dhcp-server network
add address=192.168.4.0/24 dns-server=8.8.8.8 gateway=192.168.4.1
add address=192.168.10.0/24 gateway=192.168.10.1
add address=192.168.20.0/24 gateway=192.168.20.1
/ip firewall address-list
add address=115.113.173.34 list=ssh-blacklist
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=\
    established,related hw-offload=yes
add action=accept chain=forward \
    connection-state=established,related
add action=drop chain=input connection-state=invalid
add action=accept chain=input \
    connection-state=established,related
add action=jump chain=input  in-interface=Bridge-LAN \
    jump-target=bejovo-lanbol
add action=jump chain=input in-interface=vlan-10 \
    jump-target=bejovo-vlan-10-bol
add action=jump chain=input in-interface=\
    ether1 jump-target=bejovo-internetrol
add action=jump chain=input in-interface=wireguard1 \
    jump-target=bejovo-wireguard1rol
add action=drop chain=input
add action=drop chain=forward connection-state=invalid
add action=accept chain=forward  \
    connection-state=established,related
add action=jump chain=forward in-interface=vlan-10 jump-target=\
    atmeno-vlan-10-bol-internet out-interface=ether1
add action=jump chain=forward in-interface=Bridge-LAN jump-target=\
    atmeno-lanbol-internet out-interface=ether1
add action=jump chain=forward in-interface=wireguard1 jump-target=\
    atmeno-wireguard1bol-lanba out-interface=Bridge-LAN
add action=jump chain=forward in-interface=wireguard1 jump-target=\
    atmeno-wireguard1bol-wireguard1be out-interface=wireguard1
add action=drop chain=forward
add action=add-src-to-address-list address-list=ssh-blacklist \
    address-list-timeout=none-static chain=bejovo-internetrol \
    dst-port=22 protocol=tcp
add action=add-src-to-address-list address-list=wireguard-blacklist \
    address-list-timeout=none-static chain=bejovo-internetrol \
    dst-port=13231 protocol=udp
add action=drop chain=bejovo-internetrol src-address-list=\
    ssh-blacklist
add action=drop chain=bejovo-internetrol src-address-list=\
    wireguard-blacklist
add action=accept chain=bejovo-internetrol dst-port=53231 log=\
    yes log-prefix=wireguard protocol=udp
add action=accept chain=bejovo-internetrol \
    protocol=icmp
add action=drop chain=bejovo-internetrol 
add action=accept chain=bejovo-lanbol 
add action=accept chain=bejovo-vlan-10-bol 
add action=accept chain=bejovo-wireguard1rol 
add action=accept chain=atmeno-lanbol-internet
add action=drop chain=atmeno-lanbol-internet
add action=accept chain=atmeno-vlan-10-bol-internet
add action=accept chain=atmeno-wireguard1bol-lanba
add action=accept chain=atmeno-wireguard1bol-wireguard1be src-address-list=\
    wireguard1bol-internetre
/ip firewall nat
add action=masquerade chain=srcnat
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh port=8822
set api disabled=yes
set api-ssl disabled=yes
/system clock
set time-zone-name=Europe/Budapest
/system identity
set name=hAP-ac3
/system note
set show-at-login=no

Thanks again for the suggestion. I missed the vlan filterning and setting the untagged port indeed. That was the solution.

/interface bridge
add name=Bridge-LAN vlan-filtering=yes

/interface bridge vlan
add bridge=Bridge-LAN tagged=Bridge-LAN,ether2 untagged=wifi1,wifi2,ether3 vlan-ids=10,20,99