I am currently trying to change the vlan setup in our Network to the new way.
But how would you do the inter-vlan firewall rules, if there is only 1 Bridge with all vlans inside?
Example which is currently used:
add action=accept chain=forward in-interface=bridge-vlan10 out-interface=bridge-vlan20
add action=drop chain=forward
In plain english, there is no layer 2 connectivity between vlans so only need forward firewall flter rules.
Just add what IP routing you want to permit at L3
Allow LAN to WAN
allow VLAN (some or all) to WAN
Allow VLANx to VLANy (subnet to subnet)
Allow VLAN (some or all or one vlanip) to LAN (for shared device like a printer).