I suggest you:
1. Reset router to default config ... if it is suitable for you ... check if it works to access Internet for all interfaces.
2. Configure firewall INSIDE BRIDGE to block access to Winbox-Webconfig port in the bridge filtering section
https://wiki.mikrotik.com/wiki/Manual:I ... e_Firewall instead of top level firewall as at top level you cannot check which port the packet comes from if it is part of the bridge. The source is then bridge, not particular interface.
Such configuration lets you to use all interfaces at the same level of access to the Internet, it lets you to limit/filter all traffic without thinking about different subnets/sources/interface assigments ... acces for all devices will be equally same despite medium they use ... all devices will be visible to each other (if you do not limit it manually) at the LAN side ... think about access to your NAS, TV, printer with print-server etc.
Configuring IP Firewall for bridge is the same procedure as for top level firewall ... it is just "level down". You can have more than one bridge in your LAN and then devices connected to one bridge could be filtered different way than devices in other bridge. Think about bridges with configured firewalls as of intelligent switches which limit some access at their level and pass already filtered traffic to your router. Bridge is just software based switch.