Here is the current config. Keep in mind that I've tried quite a lot already, I'm not really on the default config (anymore), not even on the stable version anymore.
But I had this issue right from the beginning, with the default wireless network it creates (with the password printed on the device), which is why I've provided that initial script above and why I've even tried so much like upgrading to the latest testing version for example.
# 2026-07-27 12:25:07 by RouterOS 7.24rc2
# software id = REMOVED
#
# model = MA53UG+HbeH
# serial number = REMOVED
/disk
add file-path=/usb1/swap file-size=1914.9MiB slot=file-usb1-swap swap=yes \
type=file
set usb1 comment=USBStick1
/interface bridge
add admin-mac=REMOVED auto-mac=no \
frame-types=admit-only-vlan-tagged name=bridge1 vlan-filtering=yes
add name=internal protocol-mode=none
add name=netbird-client
/interface ethernet
set [ find default-name=ether1 ]
set [ find default-name=ether2 ] \
l2mtu=1598
set [ find default-name=ether3 ] \
l2mtu=1598
set [ find default-name=ether4 ] l2mtu=1598
set [ find default-name=ether5 ] l2mtu=1598
/interface veth
add address="" container-mac-address=REMOVED dhcp=yes gateway="" \
gateway6="" mac-address=REMOVED name=veth-app-netbird-client
add address=172.18.0.2/24 container-mac-address=REMOVED dhcp=no \
gateway=172.18.0.1 gateway6="" mac-address=REMOVED name=\
veth-app-technitium
/interface vlan
add interface=ether1 name=UPLINK-VLAN2 vlan-id=2
add interface=bridge1 name=vlan5 vlan-id=5
add interface=bridge1 name=vlan7 vlan-id=7
add interface=bridge1 name=vlan10 vlan-id=10
add interface=bridge1 name=vlan20 vlan-id=20
/container
add hosts=technitium:172.18.0.2 interface=veth-app-technitium layer-dir=\
/usb1/apps/layers mount=/usb1/apps/technitium/config:/etc/dns:rw name=\
app-technitium remote-image=docker.io/technitium/dns-server root-dir=\
/usb1/apps/technitium/technitium_root stop-time=30s
add env="NB_DISABLE_CUSTOM_ROUTING=true,NB_HOSTNAME=REMOVED,NB_LOG_LEV\
EL=info,NB_MANAGEMENT_URL=REMOVED,NB_NAME=REMOVED,N\
B_SETUP_KEY=REMOVED,NB_USE_LEGACY_ROUTING=tru\
e" hosts=netbird-client:10.0.201.3 interface=veth-app-netbird-client \
layer-dir=/usb1/apps/layers mount=\
/usb1/apps/netbird-client/netbird-client:/var/lib/netbird:rw name=\
app-netbird-client remote-image=docker.io/netbirdio/netbird:latest \
root-dir=/usb1/apps/netbird-client/netbird-client_root stop-time=30s
/interface pppoe-client
add add-default-route=yes comment="PPPoE Internet" disabled=no interface=\
Internet-VLAN2 max-mru=1500 max-mtu=1500 name=PPPoE-Internet user=REMOVED
/interface list
add comment=Internet name=WAN
add comment=VLAN10-LAN name=VLAN10-LAN
add comment="Allow Winbox via MAC" name=WinboxMac
/interface wifi configuration
add channel.band=2ghz-be .skip-dfs-channels=10min-cac .width=20/40mhz \
comment="WiFi 2.4 GHz" country=Austria datapath.bridge=bridge1 .vlan-id=\
10 disabled=no name=WiFi-2G security.authentication-types=wpa3-psk .ft=no \
.ft-over-ds=no ssid=WiFi
add channel.band=5ghz-be .skip-dfs-channels=10min-cac .width=20/40/80mhz \
comment="WiFi 5 GHz" country=Austria datapath.bridge=bridge1 .vlan-id=10 \
disabled=no name=WiFi-5G security.authentication-types=wpa3-psk .ft=no \
.ft-over-ds=no ssid=WiFi
add channel.band=6ghz-be .skip-dfs-channels=10min-cac .width=\
20/40/80/160/320mhz comment="WiFi 6 GHz" country=Austria datapath.bridge=\
bridge1 .vlan-id=10 disabled=no name=WiFi-6G \
security.authentication-types=wpa3-psk .ft=no .ft-over-ds=no ssid=WiFi
add comment="MLD WiFi Config" datapath.bridge=bridge1 .vlan-id=10 disabled=no \
name=MLD-WiFi security.authentication-types=wpa3-psk .ft=no .ft-over-ds=\
no ssid=WiFi
add channel.band=2ghz-be .skip-dfs-channels=10min-cac .width=20/40mhz \
comment="WiFiDevices 2.4 GHz" country=Austria datapath.bridge=bridge1 \
.vlan-id=10 disabled=no name=WiFiDevices-2G \
security.authentication-types=wpa2-psk .ft=yes .ft-over-ds=yes ssid=\
WiFiDevices
add comment="WiFi 2.4 GHz Legacy" country=Austria datapath.vlan-id=10 \
disabled=no name=WiFi-2G-Legacy security.authentication-types=wpa2-psk \
.ft=no .ft-over-ds=no ssid=WiFi
add channel.band=5ghz-ax .skip-dfs-channels=10min-cac comment=\
"WiFi 5 GHz Legacy" country=Austria datapath.bridge=bridge1 .vlan-id=10 \
disabled=no name=WiFi-5G-Legacy security.authentication-types=wpa3-psk \
.ft=no .ft-over-ds=no ssid=WiFi
add comment="MLD WiFi Plus Config" country=Austria datapath.bridge=bridge1 \
.vlan-id=10 disabled=no name=MLD-WiFiPlus security.authentication-types=\
wpa3-psk .ft=no .ft-over-ds=no ssid="WiFi Plus"
add channel.band=6ghz-be .skip-dfs-channels=10min-cac .width=\
20/40/80/160/320mhz comment="WiFi Plus 6 GHz" country=Austria \
datapath.bridge=bridge1 .vlan-id=10 disabled=no name=WiFiPlus-6G \
security.authentication-types=wpa3-psk .ft=no .ft-over-ds=no ssid=\
"WiFi Plus"
/interface wifi
add configuration=MLD-WiFi configuration.mode=ap disabled=no mac-address=\
REMOVED mld-name=mld-REMOVED name=WiFi-mld \
security.authentication-types=wpa3-psk
add configuration=MLD-WiFiPlus configuration.mode=ap mac-address=\
REMOVED mld-name=mld-REMOVED name=WiFiPlus-mld
set [ find default-name=wifi1 ] configuration=WiFi-2G configuration.mode=ap \
disabled=no mld-interface=WiFi-mld name=WiFi-2G
set [ find default-name=wifi2 ] configuration=WiFi-5G configuration.mode=ap \
disabled=no mld-interface=WiFi-mld name=WiFi-5G
set [ find default-name=wifi3 ] configuration=WiFi-6G configuration.mode=ap \
disabled=no mld-interface=WiFi-mld name=WiFi-6G
add configuration=WiFiDevices-2G configuration.mode=ap disabled=no \
mac-address=REMOVED master-interface=WiFi-2G name=\
WiFiDevices-2G
add configuration=WiFiPlus-6G configuration.mode=ap mac-address=\
REMOVED master-interface=WiFi-6G mld-interface=WiFiPlus-mld \
name=WiFiPlus-6G
/ip pool
add comment=VLAN10-LAN name=LAN-DHCP ranges=10.0.0.150-10.0.0.250
add comment=NETBIRD-CLIENT name=NETBIRD-CLIENT ranges=10.0.201.2/31
/ip dhcp-server
add address-pool=LAN-DHCP comment=VLAN10-LAN interface=vlan10 name=LAN-DHCP
add address-pool=NETBIRD-CLIENT comment=NETBIRD-CLIENT interface=\
netbird-client name=NETBIRD-DHCP
/interface ppp-client
add apn=internet name=ppp-out1 port=usb2
/queue type
add kind=cake name=cake
/queue tree
add max-limit=240M name=queue-upload packet-mark=no-mark parent=PPPoE-Internet \
queue=cake
add disabled=yes max-limit=900M name=queue-download packet-mark=no-mark \
parent=bridge1 queue=cake
/app
set HA-otbr-matter required-hw-devices=ttyACM0:usb2:default:/dev/ttyACM0
set firefox use-https=no
add disabled=no network=netbird-client use-https=no yaml="name: netbird-client\
\ndescr: NetBird mesh VPN client\
\npage: https://netbird.io/\
\ncategory: networking\
\n\
\nservices:\
\n netbird-client:\
\n image: docker.io/netbirdio/netbird:latest\
\n environment:\
\n NB_SETUP_KEY: REMOVED\
\n NB_NAME: \"REMOVED\"\
\n NB_HOSTNAME: \"REMOVED\"\
\n NB_LOG_LEVEL: \"info\"\
\n NB_DISABLE_CUSTOM_ROUTING: \"true\"\
\n NB_USE_LEGACY_ROUTING: \"true\"\
\n NB_MANAGEMENT_URL: REMOVED\
\n volumes:\
\n - netbird-client:/var/lib/netbird"
set otbr network-pvid=10 required-hw-devices=\
ttyACM0:usb2:default:/dev/ttyACM0 use-https=no
set technitium disabled=no use-https=no
/app settings
set disk=usb1 lan-bridge=bridge1 router-ip=10.0.0.1
/container config
set registry-url=https://registry-1.docker.io tmpdir=/usb1/pull
/interface bridge port
add bridge=bridge1 frame-types=\
admit-only-vlan-tagged interface=ether2
add bridge=bridge1 frame-types=\
admit-only-vlan-tagged interface=ether3
add bridge=bridge1 interface=ether4 pvid=10
add bridge=bridge1 interface=ether5 pvid=10
/ip neighbor discovery-settings
set discover-interface-list=WinboxMac
/interface bridge vlan
add bridge=bridge1 comment="ALL VLANs" tagged=bridge1,ether2,ether3 vlan-ids=\
5,7,10,20
/interface list member
add interface=ether1 list=WAN
add interface=Internet-VLAN2 list=WAN
add interface=PPPoE-Internet list=WAN
add interface=vlan10 list=VLAN10-LAN
add interface=ether5 list=WinboxMac
add interface=vlan5 list=WinboxMac
/interface wifi cap
set caps-man-addresses=127.0.0.1
/interface wifi capsman
set enabled=no
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=\
WiFi-5G-Legacy name-format=%I-5G supported-bands=5ghz-ax
add action=create-dynamic-enabled disabled=yes master-configuration=\
WiFi-2G-Legacy name-format=%I-2G supported-bands=2ghz-ax
/ip address
add address=10.0.0.1/24 interface=vlan10 network=10.0.0.0
add address=10.0.5.1/24 interface=vlan5 network=\
10.0.5.0
add address=10.0.201.1/24 interface=netbird-client \
network=10.0.201.0
/ip dhcp-server lease
REMOVED
/ip dhcp-server network
add address=10.0.0.0/24 comment=VLAN10-LAN dns-server=10.0.0.1 gateway=\
10.0.0.1
add address=10.0.201.0/24 comment=NETBIRD-CLIENT dns-server=10.0.0.1 gateway=\
10.0.201.1
/ip dns
set servers=9.9.9.9
/ip firewall address-list
add address=10.0.0.10 list=REMOVED
add address=172.18.0.2 list=Technitium
/ip firewall filter
add action=accept chain=input comment=\
"ACCEPT ESTABLISHED, RELATED, UNTRACKED" connection-state=\
established,related,untracked
add action=drop chain=input comment="DROP INVALID" connection-state=invalid
add action=accept chain=input comment="ACCEPT ICMP" protocol=icmp
add action=accept chain=input comment=\
"ACCEPT TO LOCAL LOOPBACK (FOR CAPSMAN)" dst-address=127.0.0.1 \
in-interface=lo src-address=127.0.0.1
add action=jump chain=input in-interface=vlan10 jump-target=\
ZONE-LAN-to-Router
add action=jump chain=input in-interface=netbird-client \
jump-target=ZONE-NETBIRD-to-Router
add action=jump chain=input in-interface=vlan5 \
jump-target=ZONE-MIKROTIK-to-Router
add action=reject chain=input comment="REJECT EVERYTHING ELSE | input" \
reject-with=icmp-network-unreachable
add action=fasttrack-connection chain=forward comment=FASTTRACK \
connection-mark=no-mark connection-state=established,related
add action=accept chain=forward comment=\
"ACCEPT ESTABLISHED, RELATED, UNTRACKED" connection-state=\
established,related,untracked
add action=drop chain=forward comment="DROP INVALID" connection-state=invalid
add action=drop chain=forward comment="DROP ALL FROM WAN NOT DSTNATed" \
connection-nat-state=!dstnat in-interface-list=WAN
add action=jump chain=forward in-interface=vlan10 \
jump-target=ZONE-LAN-to-WAN out-interface-list=WAN
add action=jump chain=forward in-interface=\
vlan10 jump-target=ZONE-LAN-to-INTERNALAPPS out-interface=internal
add action=jump chain=forward in-interface=\
netbird-client jump-target=ZONE-NETBIRD-to-INTERNALAPPS out-interface=\
internal
add action=jump chain=forward comment="INTERNALAPPS -> WAN" in-interface=\
internal jump-target=ZONE-INTERNALAPPS-to-WAN out-interface-list=WAN
add action=jump chain=forward comment="NETBIRD -> WAN" in-interface=\
netbird-client jump-target=ZONE-NETBIRD-to-WAN out-interface-list=WAN
add action=jump chain=forward comment="LAN -> MIKROTIK" in-interface=vlan10 \
jump-target=ZONE-LAN-to-MIKROTIK out-interface=vlan5
add action=jump chain=forward comment="NETBIRD -> MIKROTIK" in-interface=\
netbird-client jump-target=ZONE-NETBIRD-to-MIKROTIK out-interface=vlan5
add action=jump chain=forward comment="MIKROTIK -> WAN" in-interface=vlan5 \
jump-target=ZONE-MIKROTIK-to-WAN out-interface-list=WAN
add action=reject chain=forward comment="REJECT EVERYTHING ELSE | forward" \
reject-with=icmp-network-unreachable
add action=accept chain=ZONE-LAN-to-Router comment="Allow ALL for now"
add action=accept chain=ZONE-LAN-to-WAN comment="Accept ALL for now"
add action=accept chain=ZONE-MIKROTIK-to-Router
add action=accept chain=ZONE-MIKROTIK-to-WAN
add action=accept chain=ZONE-LAN-to-MIKROTIK
add action=accept chain=ZONE-LAN-to-INTERNALAPPS disabled=yes
add action=accept chain=ZONE-INTERNALAPPS-to-WAN
add action=accept chain=ZONE-LAN-to-INTERNALAPPS comment="Allow DNS TCP" \
dst-address-list=Technitium dst-port=53 protocol=tcp
add action=accept chain=ZONE-NETBIRD-to-INTERNALAPPS comment="Allow DNS TCP" \
dst-address-list=Technitium dst-port=53 protocol=tcp
add action=accept chain=ZONE-LAN-to-INTERNALAPPS comment="Allow DNS UDP" \
dst-address-list=Technitium dst-port=53 protocol=udp
add action=accept chain=ZONE-NETBIRD-to-INTERNALAPPS comment="Allow DNS UDP" \
dst-address-list=Technitium dst-port=53 protocol=udp
add action=accept chain=ZONE-LAN-to-INTERNALAPPS comment=\
"Allow WebInterface Technitium" dst-address-list=Technitium dst-port=5380 \
protocol=tcp src-address-list=REMOVED
add action=accept chain=ZONE-NETBIRD-to-WAN
add action=accept chain=ZONE-NETBIRD-to-Router
add action=accept chain=ZONE-NETBIRD-to-MIKROTIK
/ip firewall nat
add action=masquerade chain=srcnat comment="masquerade for WAN" ipsec-policy=\
out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment="app NETBIRD-CLIENT network masquer\
ade rule to allow outgoing traffic be routed back" in-interface=\
netbird-client
/ip route
add comment=NETBIRD-CLIENT disabled=no distance=1 dst-address=100.0.0.0/24 \
gateway=10.0.201.3 routing-table=main scope=30 target-scope=10
/ipv6 address
add address=::1 comment="Public IPv6 for LAN" from-pool=Internet-IPv6 interface=\
vlan10
add address=fd42:10::1 comment=IPv6-VLAN10 interface=vlan10
/ipv6 dhcp-client
add add-default-route=yes comment=Internet-IPv6 interface=PPPoE-Internet pool-name=\
Internet-IPv6 pool-prefix-length=64 request=address,prefix
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
"ACCEPT ESTABLISHED, RELATED, UNTRACKED" connection-state=\
established,related,untracked
add action=drop chain=input comment="DROP INVALID" connection-state=invalid
add action=accept chain=input comment="ACCEPT ICMPv6" protocol=icmpv6
add action=accept chain=input comment="ACCEPT UDP TRACEROUTE" dst-port=\
33434-33534 protocol=udp
add action=accept chain=input comment=\
"ACCEPT DHCPv6-CLIENT PREFIX DELEGATION" dst-port=546 protocol=udp \
src-address=fe80::/10
add action=accept chain=input comment="ACCEPT IKE" dst-port=500,4500 \
protocol=udp
add action=reject chain=input comment="REJECT EVERYTHING ELSE | input" \
reject-with=icmp-no-route
add action=fasttrack-connection chain=forward comment=FASTTRACK6 \
connection-mark=no-mark connection-state=established,related
add action=accept chain=forward comment=\
"ACCEPT ESTABLISHED, RELATED, UNTRACKED" connection-state=\
established,related,untracked
add action=drop chain=forward comment="DROP INVALID" connection-state=invalid
add action=drop chain=forward comment="DROP PACKETS WITH BAD SRC IPv6" \
src-address-list=bad_ipv6
add action=drop chain=forward comment="DROP PACKETS WITH BAD DST IPv6" \
src-address-list=bad_ipv6
add action=drop chain=forward comment="rfc4890 drop hop-limit=1" hop-limit=\
equal:1 protocol=icmpv6
add action=accept chain=forward comment="ACCEPT ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="ACCEPT HIP" protocol=139
add action=accept chain=forward comment="ACCEPT IKE" dst-port=500,4500 \
protocol=udp
add action=jump chain=forward comment="LAN -> WAN" in-interface=vlan10 \
jump-target=ZONE-LAN-to-WAN out-interface-list=WAN
add action=reject chain=forward comment="REJECT EVERYTHING ELSE | forward" \
reject-with=icmp-no-route
add action=accept chain=ZONE-LAN-to-WAN
/ipv6 firewall mangle
add action=change-mss chain=forward comment="Clamp IPv6 MSS (Outbound)" \
new-mss=clamp-to-pmtu out-interface-list=WAN protocol=tcp tcp-flags=syn
/system clock
set time-zone-name=Europe/Vienna
/system identity
set name=MikroTik-Home-1
/system package update
set channel=testing
/system resource irq rps
set ether1 disabled=no
set ether2 disabled=no
set ether3 disabled=no
set ether4 disabled=no
set ether5 disabled=no
/tool mac-server
set allowed-interface-list=WinboxMac
/tool mac-server mac-winbox
set allowed-interface-list=WinboxMac