Help with firewall rules

Hello, I need some help for create the firewall rules.
I have a RB2011UiAS-RM configured:

  • ether1 WAN
  • from ether2 to ether5 LAN1 Office (192.168.2.1)
  • from ether6 to ether10 LAN2 Hotspot (192.168.3.1)
    all it’s working fine and guests authenticate trought Captive Portal correctly.
    I have two question that I don’t know how to do:
  • create Firewall Rules “filter” or “nat” (I don’t know) for allow any IP in LAN1 Office to manage and configure access point in LAN2 Hotspot;
  • if possible check why the connection from the LAN2 Hotspot is slow, instead from LAN1 Office it’s fast?

Thank you for any help

-Use firewall rule to allow LAN1 to manage AP in LAN2

-Hotspot maybe slow due to limit set, or saturated by another user.

Tony