Leaking VLANs

Hi,
I’ve turned my single bridge network to VLAN based:

WAN <-> RB750Gr3 - RB260GSP <-> RB260GSP
                 \ RB260GSP <-> RB260GSP

RB260GSP are in ether2 and ether3 of RB750Gr3, on both sides ports are set to trunk. Same between RB260GSP switches. The problem is that the communication between VLANs is possible. What I want ideally is to block communication between VLANs and open them for only selected ports or IPs but can’t make it working. Either I am cutting myself completely or all is allowed.
swow2.png
swos1.png
rb750gr3.rsc (19.4 KB)