Hello sergejs.
谢谢你的快速回复。
In the previous post I meant "on a bridge interface" and not "bridge port".
I did not put a separate HotSpot on each VLAN because I wanted to manage only one HotSpot (and save my efforts for banging my head with the User Manager v5rc4)
I added the VLANs to a bridge interface in the MT and I put forward filters so that no frames would be forwarded to/from each VLAN. The frames would only get to the MT itself (input bridge chain).
This enables me to have full control over the frames that reach the MikroTik and to have some Layer 2 security (no broadcasts pass over from VLAN to VLAN).
Right now I have a bridge interface that has the HotSpot enabled on it and it has only the HotSpot IP address and no other IP addresses. This hopefully gets rid of the mentioned problem with preferred source, seems working so far.
I hope this setup is "a good idea" ? If not - do tell how to change.
Thank you.