It is, see here why.
That’s unrelated to routing, it’s just bridging.
This does not depend on whether you choose the “one bridge per VLAN” or the “one bridge for all VLANs” approach. But I cannot see anything in your configuration export that would explain why you cannot ping a host in one subnet from a host in the other one. So maybe you are pinging Windows machines? If so, the default setting of the Windows firewall is to ignore ping requests from other subnets than the own one of the interface to which the ping request has arrived.
The firewall on your CRS itself is effectively non-existent - since the default behaviour is accept, whatever packet is not accepted by the only rule you have is accepted anyway.