Sun Mar 28, 2021 4:01 pm
If TV is the only device to be isolated and is connected to dedicated port on router, then use of VLANs is un-necessary complication. The way OP started was fine. There are a few gotchas though. The biggest might be the bug in default configuration where ports ether2-etherX are bridged but LAN IP settings (most notably address) are bound to ether2. So before removing ether2 from bridge OP must make sure ether2 is not referenced anywhere in the configuration other than in /interface bridge port. Easiest way to check it is to export configuration to text file (run /export file=anynameyouwish), open it in text editor and search for ether2.
When resolving the problem it is possible to block self from access to router. Usually it is possible to connect using winbox using MAC connectivity, so fetch it beforehand.
When ether2 is "clean of configuration", proceed according to @ykleet post. No need to make TV subnet smaller than /24, I'm sure 256 private /24 subnets are plenty enough for a typical home setup.