Which is not best practise. According to the available online Linux documentation VLAN tag management on DSA ports should be handled with the bridge v command.
There are also several threads in this forum and the OpenWrt forum on the subject (DSA VLAN).
Is the TO firewall permitting ingress from the Guest zone to the TO?
Suppose you meantime changed that (and applied) to
option ifname 'lan0' ?
From the package dump it seems strange that ethertype 802.1Q (0x8100) is not displayed (from both ends). Could you try the tcpdump with -e -vvv options?
perhaps try bridge v a dev br-guest_turris vid 3 tagged self
192.168.60.1 (which you tried to ping from the AP 192.168.60.3) is assigned to the bridge netdev but not the lan0 netdev
after fiddling around with this bridge command, I give it up.
Using eth0.3 will work for for guest devices.
Ping isn’t working, but actually I accept this.