Are you sure the CRS configuration is correct?
Well, I would say yes with the obvious caveat that the darned thing doesn't work , which means it's broken _somewhere_.
Here are the configs of the two devices. I've removed the changes I noted, and watched the video, where I think everything is right on the hAP Lite side.
Same problem. If I set the default vlan id on the hAPLite on the trunk interface to a particular vlan, it works for that vlan only. Setting it to 0 it doesn't work.
# jan/02/1970 21:55:47 by RouterOS 6.49.6
# software id = 2UIZ-IVIF
#
# model = RB941-2nD
/interface bridge
add name=bridgeVLAN
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
/interface vlan
add interface=bridgeVLAN name=vlanGUEST vlan-id=17
add interface=bridgeVLAN name=vlanLAN vlan-id=2
/interface ethernet switch port
set 0 default-vlan-id=2 vlan-header=always-strip vlan-mode=secure
set 1 default-vlan-id=17 vlan-header=always-strip vlan-mode=secure
set 3 vlan-header=add-if-missing vlan-mode=secure
set 5 vlan-mode=secure
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridgeVLAN interface=ether1 pvid=2
add bridge=bridgeVLAN interface=ether2 pvid=17
add bridge=bridgeVLAN interface=ether4
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface ethernet switch vlan
add ports=ether4,ether1,switch1-cpu switch=switch1 vlan-id=2
add ports=ether2,switch1-cpu,ether4 switch=switch1 vlan-id=17
/ip address
add address=192.168.2.3/24 interface=vlanLAN network=192.168.2.0
add address=192.168.17.3/24 interface=vlanGUEST network=192.168.17.0
/system identity
set name=B941-2nD
And the CRS
jan/02/1970 07:30:56 by RouterOS 6.49.6
# software id = AKR0-XZSF
#
# model = CRS125-24G-1S-2HnD
/interface bridge
add name=bridgeVLAN
/interface wireless
set [ find default-name=wlan1 ] disabled=no ssid=MikroTik
/interface vlan
add interface=bridgeVLAN name=vlanGUEST vlan-id=17
add interface=bridgeVLAN name=vlanLAN vlan-id=2
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=poolLAN ranges=192.168.2.100-192.168.2.199
add name=poolGUEST ranges=192.168.17.100-192.168.17.199
/ip dhcp-server
add address-pool=poolLAN disabled=no interface=vlanLAN name=dhcpLAN
add address-pool=poolGUEST disabled=no interface=vlanGUEST name=dhcpGUEST
/interface bridge port
add bridge=bridgeVLAN interface=ether2
add bridge=bridgeVLAN interface=ether3
add bridge=bridgeVLAN interface=ether4
add bridge=bridgeVLAN interface=ether5
add bridge=bridgeVLAN interface=ether6
add bridge=bridgeVLAN interface=ether7
add bridge=bridgeVLAN interface=ether8
add bridge=bridgeVLAN interface=ether9
add bridge=bridgeVLAN interface=ether10
add bridge=bridgeVLAN interface=ether11
add bridge=bridgeVLAN interface=ether12
add bridge=bridgeVLAN interface=ether13
add bridge=bridgeVLAN interface=ether14
add bridge=bridgeVLAN interface=ether15
add bridge=bridgeVLAN interface=ether16
add bridge=bridgeVLAN interface=ether17
add bridge=bridgeVLAN interface=ether18
add bridge=bridgeVLAN interface=ether20
add bridge=bridgeVLAN interface=ether21
add bridge=bridgeVLAN interface=ether22
add bridge=bridgeVLAN interface=ether24
add bridge=bridgeVLAN interface=sfp1
add bridge=bridgeVLAN interface=ether1
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface ethernet switch egress-vlan-tag
add tagged-ports=ether23,switch1-cpu vlan-id=2
add tagged-ports=ether23,switch1-cpu vlan-id=17
/interface ethernet switch ingress-vlan-translation
add customer-vid=0 new-customer-vid=2 ports=\
ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8
add customer-vid=0 new-customer-vid=17 ports=\
ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16
add customer-vid=0 new-customer-vid=2 ports=\
ether17,ether18,ether20,ether21,ether22,ether24
/interface ethernet switch vlan
add ports="ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether17,ether\
18,ether20,ether21,ether22,ether24,switch1-cpu" vlan-id=2
add ports="ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether2\
4,switch1-cpu" vlan-id=17
/ip address
add address=192.168.2.1/24 interface=vlanLAN network=192.168.2.0
add address=192.168.17.1/24 interface=vlanGUEST network=192.168.17.0
/ip dhcp-server network
add address=192.168.2.0/24 dns-server=8.8.8.8 gateway=192.168.2.1 netmask=24
add address=192.168.17.0/24 dns-server=8.8.8.8 gateway=192.168.17.1 netmask=24
/system identity
set name=RS125-24G-1S-2
With the goal to have a trunk between the two on hAPLite: ether 4 and CRS125 on ether 24 for VLANs 2 and 17, with (for the moment) full connectivity across all the ports and vlans. I'm using ether3 on the hAP to manage it, and ether 19 on the CRS, specifically so I don't cut myself off at the knees with other configuration.