My solution to the whole thing is I moved to use a MikroTik RB750Gr3 with Netgear WAC510 instead. The whole experience is much better over there compared to do all the ASUS/Merlin scripting.
Thanks for the info.
Actually I've already ordered a Mikrotik hex poe 960pgs to replace RT-AC68U. 960PGS is a little bit weaker than asus 68U on the routing and NAT but I need its POE to feed couple cameras. It is much easier to configure VLAN on RouterOS to work with Cisco Aironet AP.