Hi,
Check your configuration and ensure the SSID is tagged properly with the correct VLAN ID. From the AP, check and ensure the VLAN ID is allowed on your switches trunk ports all the way to the MX. Lastly from the MX's Addressing and VLANs' page, verify that the VLAN is allowed on those ports.
For the Radius authentication failures, verify from the server logs what is the error. You may also take packet captures on the wired interface of the AP while a client is connecting so you can see the packet exchanges between the AP and RADIUS server. It should tell you whether the RADIUS is sending access-reject or if the AP is not sending the access-request at all.
hope this helps.
Please hit kudos if you found this post helpful and/or click "accept as solution" if this solved your problem.