I created a new VLAN 20 for GUEST access:

The new VLAN 20 will be NATed before goes to Internet with 192.168.1.100 address.
I want that the new 192.168.2.0/24 network could not access to the default (VLAN 1) 192.18.1.0/24 network.
Is it possible to create some ACL or firewall rules in the OS6350? The new GUEST network will only have access to Internet.
I will appreciate your help.
Best regards.

