Hi! I'm new to RouterOS and the MikroTik line, and have spent the past two weeks trying to get a working VLAN implementation on my RB960PGS. I'm coming in to the home stretch and have DHCP going on the various VLANs, which are pointing to the correct ports. The last thing I need to do is get these VLANs talking to the Internet through the WAN port. Having spent the last 24 hours fiddling with firewall rules, I'm stumped.
I've rolled my configuration back to a baseline state where the VLAN's are on the right ports and the router is serving DHCP on each. VLAN 1 is routing to the Internet as it always has. Three additional VLAN's need Internet access but should otherwise be firewalled from one another: 16, 24, and 48. The VLANs are set up using the "new" (>v6.41) bridge method.
I can't figure out where on earth to go from here. I've tried setting up forwarding rules between the VLAN interfaces and the WAN port, at various times trying to involve the bridge just for giggles, with no success. I'm fairly certain I need a rule to forward traffic from each of the VLAN's to the WAN port, and vice-versa but haven't the foggiest what this should look like. My past experience with firewalls (iptables specifically) isn't translating well to the MikroTik.
I've attached a configuration export showing where I am now. I would be immensely appreciative of any and all suggestions.