I’m reposting an idea I had in a different subsection.
I would like to see the added option of WAN as part of the VLAN grid, where you could easily block WAN access to the VLANs. As an example, I would like to block Internet access from all devices on the X1 VLAN (IoT devices). I would simply uncheck the box in WAN column for row X1. I could also uncheck the box X1 column for WAN row.That way the internet can’t connect to the X1 VLAN. Actually, only X3 would have a check in the WAN row because it hosts my Web hosting servers.
WAN LAN Guest X1 X2 X3 (DMZ)
WAN………. -…….-…..- ….-…..X
LAN…..X…..X ……X…..X…..X…..X
Guest…X…..-…….-…..-…..-…..-
X1……-…..-…….-…..X…..-…..-
X2……X…..X…….-…..-…..X…..X
X3……X…..-…….-…..-…..-…..X
This would be a lot more elegant and a lot less time consuming to setup than having to identify all the IoT devices and adding them to a profile. In the meantime, Support did suggest a functional alternative (but not as elegant;-) – setup a VPN service for X1 but don’t connect it to anything (add local LAN ip range to exclude LAN traffic from VPN tunnel.