hello
i am looking for an approach on how to effectively isolate vlans and different dhcp interfaces. by default when making a vlan (or creating a hotspot) on an interface i can access and ping main (with default configuration) network subnet BUT NOT the opposite (from main to hotspot or vlan). this is unwanted because i want to isolate ALL vlans and dhcp server interfaces from accessing each other. i have achived this by adding firewall and routing rules but i believe that there must be a simpler way to make the opposite and add firewall rules to allow communication istead of dropping it.
any ideas i havent thought already???
i think maybe unchecking ip forward and adding manually firewall rules for routing to wan???