Hi, honestly, I have never had this kind of problems with inter-vlan routing on Zs, and there are a lot of things which could interfere with traffic’s flow , eg … client isolation on APs/SSID ?? I would recomend to enable logging, on the previously created rules, and then investigate on these…also , even though the default policy is drop , sometime is useful add , as last rule , a “drop-log” *everything, for further analisys.