HI,
As discussed.
Config
# model = RouterBOARD 931-2nD r2
/interface bridge
add fast-forward=no name=bridge1
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n disabled=no frequency=auto mode=ap-bridge ssid=********
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=w****** *******="*****" mode=****** supplicant-identity=*******
/ip pool
add name=dhcp_pool0 ranges=192.168.137.2-192.168.137.254
/ip dhcp-server
add address-pool=dhcp_pool0 disabled=no interface=bridge1 name=dhcp1
/interface bridge port
add bridge=bridge1 interface=wlan1
add bridge=bridge1 interface=ether3
/interface bridge settings
set allow-fast-path=no
/ip firewall connection tracking
set enabled=yes
/interface list member
add interface=ether1 list=WAN
add interface=ether2 list=WAN
add interface=bridge1 list=LAN
/ip address
add address=192.168.137.1/24 interface=bridge1 network=192.168.137.0
/ip dhcp-client
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=ether1 use-peer-dns=no
add add-default-route=no dhcp-options=hostname,clientid disabled=no interface=ether2 use-peer-dns=no
/ip dhcp-server network
add address=192.168.137.0/24 gateway=192.168.137.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8,8.8.4.4,10.0.0.254
/ip firewall filter
add action=accept chain=input connection-state=established,related
add action=accept chain=input protocol=icmp
add action=drop chain=input in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface-list=WAN src-address=192.168.137.0/24
/ip firewall service-port
set sip ports=5060,5161 sip-timeout=10s
/ip route
add check-gateway=ping distance=1 gateway=8.8.8.8
add check-gateway=ping distance=2 gateway=8.8.4.4
add distance=1 dst-address=8.8.4.4/32 gateway=10.0.0.254 scope=10
add distance=1 dst-address=8.8.8.8/32 gateway=192.168.0.1 scope=10
/system clock
set time-zone-name=Africa/Johannesburg
/system routerboard settings
set silent-boot=no
/system script
add dont-require-permissions=no name=script1 owner=admin policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
source="/ip firewall connection remove [find where connection-type=sip]"
The setup communicates with a Cloud PBX running on port 3333