router management best practise

Good morning, this is my first post so be gentle with me :slight_smile:

I have eventually got around to sorting out my home network, before it was the usual everything on one network behind the ISP router, this upgrade is long overdue.

I have inserted a couple of switches, and placed a Mikrotik RB3011UiAS-RM behind the internet VDSL router, I have decided to keep the internet facing modem routing rather than in bridge mode and use double NAT for external access but that is not the question. I’m also replacing all my Edimax access points with Mikrotik, I have several outbuildings so I have 5 APs in total, most are being replaced with HAP-lite but I have one HAP AC2 for the house. The plan is to use the APs in bridge mode with a trunk to each, one VLAN for guest, one for internal WLAN each with different SSIDs.

I’ve attached a high level diagram of the network I have built, all up and working except for the APs. The question I have is about managing the network devices. Where I work we have a completely separate management network, this is probably overkill for home networks. Should I create a separate management VLAN and trunk this out to the router and APs and only allow access to this network from my internal trusted wired LAN or is there a better way?

I’ve been flying a desk and away from the tools for a long time hence the ask.
home network diagram.jpg
Cheers
Andy