Restrict/Isolate wireless interface from local/lan interface

I need to make changes to my 2011UiAS-2HnD so the wireless interface is restricted from accessing the local/lan interface and Im unsure how to go about it. I have to make the change due to PCI compliance.

Looking for recommendations.

Current configuration has wifi and local interfaces on the same subnet connected with bridge.

You can route instead and set firewall rules that fulfill your needs. Or you can keep the bridge and switch the bridge firewall on and set its rules accordingly.

another way is use bridge filter rules to block traffic at bridge level without using ip firewall on bridge

Thank you for the info. I was able to figure it out with horizon spilts.