Sorry to reopen but issue is Back.
Had a situation where my router was booting ok but it was not offering any service and so i did a reset. restored from the last backup. The issue came back the "solution" did not resolve.
It presents as devices connected to the mikrotik wireless iinterface cant connect to LAN Devices include SMB RDP and web consoles.
RB version is 7.1.5
# mar/29/2022 08:00:14 by RouterOS 7.1.5
# software id = 82QS-JV7P
#
# model = 2011UiAS-2HnD
# serial number =
/interface bridge
add comment="LAN Bridge" name=home protocol-mode=stp
/interface ethernet
set [ find default-name=ether1 ] disabled=yes
set [ find default-name=ether2 ] disabled=yes
set [ find default-name=ether3 ] comment="Switch LAN"
set [ find default-name=ether4 ] comment="Desk Cable LAN"
set [ find default-name=ether5 ] comment=LAN-Homelab
set [ find default-name=ether6 ] advertise="10M-half,10M-full,100M-half,100M-f\
ull,1000M-half,1000M-full,10000M-full,2500M-full" disabled=yes
set [ find default-name=ether7 ] disabled=yes
set [ find default-name=ether8 ] comment=WANURSALink
set [ find default-name=ether9 ] advertise=\
10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full comment=\
GPONCPE
set [ find default-name=ether10 ] disabled=yes poe-out=off poe-priority=5
set [ find default-name=sfp1 ] disabled=yes
/interface pppoe-client
add comment="GPON Faiba" disabled=no interface=ether9 max-mtu=1500 name=\
JTLFaiba user=P
/interface ethernet switch port
set 6 vlan-mode=fallback
set 7 vlan-mode=fallback
set 8 vlan-mode=fallback
set 9 vlan-mode=fallback
set 10 vlan-mode=fallback
set 12 vlan-mode=fallback
/interface list
add comment=WAN name=WAN
add comment=LAN name=LAN
add comment=Phone name=LTE
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] comment=Default eap-methods="" \
management-protection=required mode=static-keys-required \
supplicant-identity=MikroTik
add authentication-types=wpa2-psk comment=DefaultHome disable-pmkid=yes \
eap-methods="" mode=dynamic-keys name=Home supplicant-identity=""
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n bridge-mode=disabled \
channel-width=20/40mhz-XX comment="LAN Bridge" country=kenya disabled=no \
distance=indoors frequency=2452 hw-retries=10 installation=indoor \
max-station-count=100 mode=ap-bridge name=wireless security-profile=Home \
ssid=twitwi tx-power=7 tx-power-mode=all-rates-fixed wireless-protocol=\
802.11 wps-mode=disabled
/interface wireless nstreme
set wireless comment="LAN Bridge"
/interface wireless manual-tx-power-table
set wireless comment="LAN Bridge"
/ip pool
add name=home ranges=
/ip dhcp-server
add address-pool=home interface=home lease-time=1d name=home
/port
set 0 name=serial0
/queue simple
add burst-limit=10M/20M burst-threshold=10M/20M burst-time=5s/5s disabled=yes \
max-limit=10M/20M name=queue1 target=ether5
/snmp community
set [ find default=yes ] addresses=25 name=pablo
/user group
add name=group1 policy="local,reboot,read,test,winbox,password,web,!telnet,!ss\
h,!ftp,!write,!policy,!sniff,!sensitive,!api,!romon,!dude,!tikapp,!rest-ap\
i"
/interface bridge port
add bridge=home ingress-filtering=no interface=ether4
add bridge=home ingress-filtering=no interface=ether5
add bridge=home ingress-filtering=no interface=ether3
add bridge=home fast-leave=yes interface=wireless
/ip neighbor discovery-settings
set discover-interface-list=!none
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface list member
add interface=ether8 list=WAN
add interface=home list=LAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=wireless list=LAN
add interface=ether9 list=WAN
add interface=ether3 list=LAN
add interface=JTLFaiba list=WAN
add list=WAN
/ip address
add address=LAN.1/26 comment=Home interface=home network=LAN.0
/ip cloud
set ddns-update-interval=3h
/ip dhcp-client
add add-default-route=no comment=GPONFaibaCPE interface=ether9 use-peer-dns=\
no use-peer-ntp=no
add add-default-route=no comment=URSALink interface=ether8 script="/ip dns sta\
tic remove [find where name=cellrouter.lan]\r\
\n:if (\$bound=1) do={/ip dns static add name=cellrouter.lan address=\$\"g\
ateway-address\"}" use-peer-dns=no use-peer-ntp=no
/ip dhcp-server network
add address=LAN.0/26 dns-server=LAN.1 gateway=LAN.1
/ip dns
set allow-remote-requests=yes cache-max-ttl=2d max-concurrent-queries=1000 \
max-concurrent-tcp-sessions=200 max-udp-packet-size=1024 \
query-server-timeout=3s servers=\
1.1.1.1,208.67.222.222,8.8.8.8,8.8.4.4,208.67.220.220
/ip firewall address-list
add address=LAN.2-LAN.254 list=allowed_to_router
add address=139.162.40.38 list=plex
/ip firewall filter
add action=accept chain=forward comment="Established, Related" \
connection-state=established,related
add action=accept chain=input comment="default configuration" \
connection-state=established,related,untracked
add action=accept chain=input disabled=yes src-address-list=allowed_to_router
add action=accept chain=input protocol=icmp
add action=drop chain=input connection-state=invalid
add action=fasttrack-connection chain=forward comment=FastTrack \
connection-state=established,related hw-offload=yes
add action=drop chain=forward comment="Drop invalid" connection-state=invalid \
disabled=yes log=yes log-prefix=invalid
add action=accept chain=forward disabled=yes dst-address-list=plex dst-port=\
80,443 protocol=tcp
add action=drop chain=forward disabled=yes out-interface-list=WAN \
src-address=LAN.34
add action=drop chain=input comment=winboxdrop dst-port=8291 \
in-interface-list=WAN protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat comment=WAN out-interface-list=WAN
add action=masquerade chain=srcnat comment=GPON disabled=yes out-interface=\
JTLFaiba
add action=masquerade chain=srcnat comment=Faiba disabled=yes out-interface=\
*E
add action=src-nat chain=srcnat disabled=yes out-interface=*E to-addresses=\
192.168.0.10
/ip route
add comment=Faiba disabled=no distance=1 dst-address=0.0.0.0/0 gateway=\
JTLFaiba pref-src="" routing-table=main scope=30 suppress-hw-offload=no \
target-scope=10
add comment=Cellular disabled=no distance=2 dst-address=0.0.0.0/0 gateway=\
ether8
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh address=LAN.0/26 disabled=yes port=2200
set www-ssl certificate=home disabled=no port= tls-version=only-1.2
set api disabled=yes
set winbox address=LAN.0/26
set api-ssl address=LAN.0/26 certificate=home disabled=yes \
tls-version=only-1.2
/ip traffic-flow
set enabled=yes
/lcd
set enabled=no touch-screen=disabled
/snmp
set enabled=yes trap-generators=""
/system clock
set time-zone-autodetect=no time-zone-name=Africa/Nairobi
/system identity
set name=home
/system logging
add action=disk prefix=critical topics=critical
add action=disk prefix=warning topics=warning
add action=disk prefix=error topics=error
add action=disk prefix=info topics=info
add action=disk prefix=debug topics=debug
add action=disk prefix=poe topics=poe-out
/system ntp client
set enabled=yes
/tool bandwidth-server
set enabled=no
add
/tool mac-server
set allowed-interface-list=none
/tool mac-server ping
set enabled=no