Need help on config secured VLAN

Hi All,

I need help for VLAN:

My LAN config as follow:
10.100.100.0/24
Mikrotik ver 6.0.x on 10.100.100.3
Internal DNS abd Email server 10.100.100.6
Connected to Internet 100 Mbps
App server 10.100.100.9
DB Server 10.100.100 10
KAV antivirus server 10.100.100.11
TPLink L3 switch located in server room

I have a plan to create 2 secured VLAN for GA and Accounting users as follow:

VLAN 100 for GA 192.168.100.0/24
VLAN 200 for Accounting 192.168.200.0/24

all of both VLAN connected to another TPLink L3 switch that located in GA & Accounting ‘s area

My questions are, how to configure:

to not allow users in VLAN 100 communicate with VLAN 200 vice versa.

to allow KAV antivirus to update to both VLANs
to only allow both VLAN users to connect to App server
to allow users to connect to internet via LAN
to allow user to connect to Email server in LAN.

Any help would be greatly appreciated

Thanks a lot in advance

Don