Sorry for that, forget the vlan link itself
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1
As I stated you dont nee the vlan in your simple config.
Ether 5 just gets its own ethernet setup, pool, address etc, and is NOT on the bridge
The ether ports 2-4 are on teh bridge and assign the bridge the address, dhcp etc.
The firewall rules you can use to block traffic from bridge subnet to etherport 5 subnet (and there are at least 2 approaches for that).
HOWEVER what are stuff are you trying to do here.
WHY IS WWW even turned on ?
If you are using plain internet to access your router you are LOCO.
Remove it asap.
The only safe way to access your router remotely is via VPN, port knocking is another method that is not ideal and temporary until you get VPN established.