Hi,
from a quick view, noticed that the ip addresses are all configured to the ether3 physical interface, not to the VLAN interfaces.
This miight solve issue 1.
For issue 2 you may add some firewall rules to the forward chain in order to block some traffic.
Cheers