and f course add-src-mac-to-list and add dst-mac-to-list (and hopefully also remove-src/dst-mac-from-list...+1 for mac-address-list in bridge filter/nat and mac-address-list along with ip firewall rule src-mac-address matcher
Don't you also have to allow DHCP (UDP port 67) from vlan-guestI use a similar setup except there's a switch in between.
5. Input: Accept UDP port 53 (DNS) from vlan-guest