Firmware 8.5 and VLAN/Firewall with IOT devices

I’m having trouble after upgrading from Fimware 8.4 to Firmware 8.5 on my Balance One.

The setup:

  • one untagged network for my trusted devices (with a corresponding WiFI SSID)
  • one VLAN for my IOT devices (with corresponding WiFi SSID)
  • An IOT device (Gecko In Touch 2) is connected via a Balance One ethernet port set to an VLAN Access mode
  • I do not have layer 2 isolation on my IOT VLAN Wifi networks
  • but I do have a firewall rule which blocks any connection from the IOT VLAN to the un-tagged LAN (but does not block connections in the opposite direction)
  • Bonjour forwarding set up between the two networks.

In Firmware 8.4, this worked as expected.

After upgrading to 8.5, I’m unable to access this one specific device (Gecko InTouch2) - it can no longer be seen from my untagged WiFi network.
However, if I switch my iPad from my trusted WiFi to the IOT-only VLAN WiFi network, I can now access the IOT device.

It appears that something has changed between firmware 8.4 and 8.5.

(Edit: this is a description of my IOT / VLAN setup): IOT (Internet of Things) security with Peplink - #5 by soylentgreen

I believe I’ve figured out this problem, see Outbound Policy + Firewall + VLAN bug in firmware 8.5