This is easy peasy.
I would rather get wired connectivity on the router if possible but understand you are limitted.
On the Mikrotik TWO VLANS
One vlan is for a local port going out hotel wifi internet
One vlan is for other ports going out home internet AND 5ghz wifi.
Do config from off bridge port once setup. Setup PC ipv4 settings to 192.168.55.2 and your in.
\
serial number = ***
/interface bridge
add name=bridge vlan-filtering=no { change to yes at end of config }
/wireguard
add name=wireguardHotel mtu=1420 listening-port=XXXXX does not have to be same as home setting.
/interface ethernet
set [ find default-name=ether1 ] name=wan1 disabled=yes { enable if using for wired input from hotel }
set [ find default-name=ether2 ] name=localPort2
set [ find default-name=ether3 ] name=homePort3
set [ find default-name=ether4 ] name=homePort4
set [ find default-name=ether5 ] name=OffBridge5
/interface vlan
add interface=bridge name=vlanLocal vlan-id=5
add interface=bridge name=vlanHome vlan-id=10
/interface list
add name=WAN
add name=LAN
add name=TRUSTED
/interface wireless
SETUP AS REQUIRED
2GHZ for WAN connectivity
5GHZ for normal AP type activity.
_/ip pool
add name=dhcp_pool5 ranges=192.168.5.11-192.168.88.254
add name=dhcp_pool10 ranges=192.168.10.11-192.168.77.254
/ip dhcp-server
add address-pool=dhcp_pool3 interface=bridge name=dhcp5
add address-pool=dhcp_pool10 interface=bridge name=dhc_p10
/routing table
add disabled=no fib name=via-home
/interface bridge port
add bridge=bridge ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
interface=localPort2 pvid=5
add bridge=bridge ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
interface=homePort3 pvid=10
add bridge=bridge ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
interface=homePort4 pvid=10
add bridge=bridge ingress-filtering=yes frame-types=admit-only-untagged-and-priority-tagged
interface=5GHzwifiName pvid=10
/ip neighbor discovery-settings
set discover-interface-list=TRUSTED
/interface bridge vlan
add bridge=bridge tagged=bridge untagged=localPort2 vlan-id=5
add bridge=bridge tagged=bridge untagged=homePort3,homePort4,5GHz-wifiName vlan-ids=10
/interface list member
add interface=2GHz-wifiName list=WAN
add interface=wan1 list=WAN disabled-yes { enable if connecting wired to hotel }
add interface=vlanLocal list=LAN
add interface=vlanHome list=LAN
add interface=vlanHome list=TRUSTED
add interface=Offbridge5 list=TRUSTED
/ip address
add address=198.168.5.1/24 interface=vlanLocal network=198.168.5.0
add address=192.168.10.1/24 interface=vlanHome network=192.168.10.0
add address=10.10.20.2/24 interface=wireguardHotel network=10.10.20.0
/interface wireguard peers
add allowed-address=10.10.20.0/24 interface=wireguardHotel endpoint-address=mynetnameHomeMT.net
endpoint-port=ABCDE public-key="......." persistant-keep-alive=35s
/ip dhcp-server network
add address=192.168.5.0/24 dns-server=192.168.5.1 gateway=192.168.5.1
add address=192.168.10.0/24 dns-server=10.10.20.1 gateway=192.168.10.1
/ip dns
add set allow remote servers, servers=1.1.1.1,8.8.8.8
/ip dhcp-client
add interface=ether1 use-peer-dns=no use-default-route=yes disable=yes { enable if wired connection to Hotel }
add interface=2GHzwifiName use-peer-dns=no use-default-route=yes
/ip firewall filter
add action=accept chain=input connection-state=established,related,untracked
add action=drop chain=input connection-state=invalid
add action=accept chain=input protocol=icmp
add action=accept chain=input comment="admin access" in-interface-list=TRUSTED
add action=accept chain=input comment="users to services" dst-port=53
in-interface-list=LAN protocol=udp
add action=accept chain=input comment="users to services" dst-port=53
in-interface-list=LAN protocol=tcp
add action=drop chain=input comment="drop all else" { put this rule in last }
+++++++++++++
add action=fasttrack-connection chain=forward connection-state=established,related
add action=accept chain=forward connection-state=established,related,untracked
add action=accept chain=forward comment=users to home internet" src-address=192.168.10.0/24 out-interface=wireguard1
add action=accept chain=forward comment="local internet" in-interface-list=LAN out-interface-list=WAN
add action=drop chain=forward comment="drop all else"
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN
add action=dstnat chain=dstnat src-address=192.168.10.0/24 dst-port=53 protocol=udp to-address=10.10.20.1
add action=dstnat chain=dstnat src-address=192.168.10.0/24 dst-port=53 protocol=tcp to-address=10.10.20.1
/ip route
add dst-address=0.0.0.0/0 gateway=wireguardHotel routing-table=via-home
/routing rule
add action=lookup-only-in-table src-address=192.168.10.0/24 table=via-home
{ if you want local access if tunnel is not working change action to simply: lookup
/tool mac-server
set allowed-interface-list=NONE
/tool mac-server mac-winbox
set allowed-interface-list=TRUSTED