(1) Not a problem.
Once you have made the necessary corrections, the final step will be this......
/interface bridge
add name=BR1 protocol-mode=none vlan-filtering=yes
++++++++++++++++++++++++++++++++
(2) Strangely you have 3 vlans but four of everything else........... I hope you didnt keep one subnet without a vlan, will have to zap you with a taser.........
Ahh I see the problem, Y
OU ONLY need to set the IP address on ether10 nothing else.................. for a safe entry point to the router.
(3) Without a network diagram little harder to discern intent but looks like you have vlan10 going to dumb devices on ether2, ether3 and wlan1, and you have vlan20 going to dumb devices on ether4,5 and then you have vlan99 going to dumb devices on ether9, ether10.
Mistake, you dont want vlan99 going to ether10 because ITS NOT SUPPOSED TO BE ON THE BRIDGE!
(4) Forgot to add BASE vlan to BASE interface list as a member.
(5) Add a few missing items that are not visible on the config.
/ip neighbor discovery-settings and /tool mac-server mac-winbox
+++++++++++++++++++++++++++++++++++++++++++++++++++++
To enter the router and config from ether 10, just set an ipv4 IP address of 10.0.10.0.5 on the laptop or PC connecting up on ether10 for example.
What you are missing completely is firewall rules, so this should not be hooked up directly to the internet. Thus ensure you read this
and add as appropriate........
viewtopic.php?t=180838
/interface bridge
add name=BR1 protocol-mode=none vlan-filtering=yes
/interface ethernet
set [ find default-name=ether10 ] name=ether10-safe
/interface wireless
set [ find default-name=wlan1 ] disabled=no frequency=auto hide-ssid=yes \
mode=ap-bridge ssid=theFarmSvc
/interface vlan
add interface=BR1 name=BASE_VLAN vlan-id=99
add interface=BR1 name=BLUE_VLAN vlan-id=10
add interface=BR1 name=GREEN_VLAN vlan-id=20
/interface list
add name=WAN
add name=VLAN
add name=BASE
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
supplicant-identity=MikroTik
/ip pool
add name=BLUE_POOL ranges=192.168.3.2-192.168.3.254
add name=GREEN_POOL ranges=192.168.203.2-192.168.203.254
add name=BASE_POOL ranges=192.168.0.10-192.168.0.20
/ip dhcp-server
add address-pool=BLUE_POOL interface=BLUE_VLAN name=BLUE_DHCP
add address-pool=GREEN_POOL interface=GREEN_VLAN name=GREEN_DHCP
add address-pool=BASE_POOL interface=BASE_VLAN name=BASE_DHCP
/port
set 0 name=serial0
/interface bridge port
add bridge=BR1 interface=ether2 pvid=10
add bridge=BR1 interface=ether3 pvid=10
add bridge=BR1 interface=wlan1 pvid=10
add bridge=BR1 interface=ether4 pvid=20
add bridge=BR1 interface=ether5 pvid=20
add bridge=BR1 interface=ether9 pvid=99
/interface list member
add interface=ether1 list=WAN
add interface=BLUE_VLAN list=VLAN
add interface=GREEN_VLAN list=VLAN
add interface=BASE_VLAN list=BASE
add interface=ether10-safe list=BASE
/ip address
add address=10.10.0.1/24 interface=ether10-safe network=10.10.0.0
add address=192.168.3.1/24 interface=BLUE_VLAN network=192.168.3.0
add address=192.168.203.1/24 interface=GREEN_VLAN network=192.168.203.0
add address=192.168.0.1/24 interface=BASE_VLAN network=192.168.0.0
/ip dhcp-client
add interface=ether1
/ip dhcp-server network
add address=192.168.0.0/24 dns-server=192.168.0.1 gateway=192.168.0.1
add address=192.168.3.0/24 dns-server=192.168.0.1 gateway=192.168.3.1
add address=192.168.203.0/24 dns-server=192.168.0.1 gateway=192.168.203.1
/ip dns
set allow-remote-requests=yes servers=9.9.9.9
/ip neighbor discovery-settings
set discover-interface-list=BASE
/tool mac-server mac-winbox
set allowed-interface-list=BASE
/system clock
set time-zone-name=Europe/Rome
/system identity
set name=MTtheFarm