DSA VLAN - bridge without or with wan Port

Hello,
My configuration Zyxel Multy M1 WSM20
Openwrt 23.05.02
one bridge with lan1, lan3 and the 2 wifi radio
one bridge with lan2 port using vlan tagged
wan port not part of any bridge.
All is working fine:
wifi clients and machines connected to lan1 and lan2 ports are under 192.168.7 subnet, have ipv6 adrdresses and have access to internet.
Esx VM with vlan tag 7 connected to lan2 port are under 192.168.17 subnet and have access to internet.
The wan port is connected to my ISP.
My first question is:
is it better to have all ports, lan , wan et wifi radio on one bridge with this router using mt7621 soc?
The second, in case if I will put rb5009 ( with routeros or perhaps openwrt) to have wireguard and adguard home, I want to have wan port working as trunk. So same question, one bridge with all port or a bridge with only wan port and vlan filtering enable with tag vlan set on it?

This is my first experience with openwrt and I like it.
As ipv6 delegation are working better with openwrt and routeros with my ISP, I will leave opnsense as my main router.
So I am replacing my hardware steps by steps using if possible openwrt as it is working like a charm