But I only want to block pings from de subnet to the subnet
wlan1 has the subnet
ether1 has the subnet
I want that users can ping to internet addresses.
You could use these as these rules block icmp-ping only (but allows other icmp packets to travel through (which in most cases is a good thing for error response))
add action=drop protocol=icmp icmp-options=0:0 src-address= dst-address=
add action=drop protocol=icmp icmp-options=0:0 src-address= dst-address=
add action=drop protocol=icmp icmp-options=8:0 src-address= dst-address=
add action=drop protocol=icmp icmp-options=8:0 src-address= dst-address=