You can set the switch to accept only tagged packets on the ingress port. To do so, set "VLAN Receive = only tagged" under the "VLAN" tab for Port1-Port4.
To filter out all unknown VLANs and allow only 10,20,30, you need to set VLAN mode to either enabled or strict. Under the "VLAN" tab set "VLAN Mode = enabled/strict" for Port1-Port4. After than, open "VLANs" tab, press "append", specify "VLAN ID = 10", set "not a member" for each port that should not forward this VLAN ID (in your case, set "not a member" to Port5 and SFP. Repeat the steps for VLAN20 and VLAN30. That is it! Though you might want to consider to disable unused ports for security reasons.
Don't forget to apply all changes.