Make VLANs in the switch set every one to "tagged" on both the trunk ethernet cable and the CPU port.
Make a separate bridge interface for each VLAN.
The VLAN that you want to be able to log into the router for administration can be the original "lan". It should have a static IP that does not conflict with anything and DHCP server turned off both v4 and v6.
The ones that are going to be completely dumb bridges from wired to wifi can be set with protocol "Unmanaged" or None.
In each bridge, have the corresponding wifi AP and one of the eth0.x ethernets.
Do not connect anything to eth0 by itself. Always specify the VLAN.
Suggest making a temporary AP that is in the LAN bridge for doing this setup. This way if you lose connection by Ethernet you can still log in on wifi.
(Last edited by mk24 on 18 Jul 2017, 19:51)