I bought the Mikrotik Hap ax3 with the hope to improve security and privacy settings without knowing I dig a hole for myself. At the moment, I am trying to set up separations between the categories of devices using VLANs. The idea is, I will have a wifi interface for each VLAN group, and switch to them as needed.
I would like to set up these Mikrotik settings in a Mikrotik Hap ax3
Bridge_Main_Devices: Use VLAN 10 for all devices under normal usages
Has My_5GHz and My_2GHz wifi interfaces
Bridge_Admin: Use VLAN 100, only used to configurate NAS (and potentially router. How is it possible?)
Has ether2_NAS port
Bridge_IOT - Use VLAN 20
Has My_Devices (2.4 GHz wifi interface)
Has ether4_Verisure_hub port
My_X_Devices (2.4 GHz wifi interface) that use VLAN 30 (for unsafe IOT devices)
My_Guests (5 GHz wifi interface) that use VLAN 40 for guestgeometry vibes
This set up would leave me with 5 wifi SSID, which will clutter the wifi list (I guess I can hide some). Currently, no matter what I do, I can only create 2 wifi interfaces (1x5Ghz and 1x2Ghz). Is this the limitation of mikrotik?
Another way would be having only 1 wifi network and change the VLAN as needed, but I found that quite inconvenience comparing to switching to a saved wifi.
How do you guys handle VLAN? Am I doing it correctly?
P/s: Btw, can someone please explain me “VLAN Filtering” please? It seems like the VLAN works without enabling it, so why should I bother enabling it?