RB4011 VLAN / IP filter miskonfiguration?

Please keep in mind. Youtube can also get you into trouble LOL.

The input chain is for traffic to and from the router itself. WAN to Router, LAN to router, Router to WAN, Router to LAN
The Forward chain rules are for traffic through the Router LAN to WAN, WAN to LAN, LAN to LAN

What will help you help me, is a description of the requirement without mention of the config but in terms of your users.
What individuals or groups or devices etc should be able to do or not do.

The best reference on vlans follows, other than that asking here is a good idea.
http://forum.mikrotik.com/t/using-routeros-to-vlan-your-network/126489/1