Its a basic firewall rule of allowing vlanxx to vlanyy.
In your case its more specific allow vlanxx to IP address on vlan yy
Even more so allow vlanxx to IP address on port zz on vlan yy
add action=accept chain=forward comment=“allow VLANXX to Synology”
in-interface=VLANXX dst-address=synology_IP dst-port=32400