Do you want single user access to single user access blocked or was that only an example and you want the TWO LANS to be isolated from each other.
If the latter, the rules implemented above wont work if they are all on the same LAN interface list from my limited understanding. The IP firewall rules will work at layer3 only but not at layer 2.
Suggest putting one LAN on a bridge and the other not on the bridge or use two separate bridges which will block at layer 2.
I might have that mixed up but thats what happens when you get advice from fellow newbies.