@MartinLangmaid, below is the functionality of the firewall at Advanced > Access Rules:
Outbound firewall = LAN/VLAN —Allow/Block—> WAN
Inbound firewall = WAN —Allow/Block—> LAN/VLAN
Internal firewall = LAN/VLAN/SpeedFusion networks —Allow/Block—> LAN/VLAN/SpeedFusion networks
Local Service Firewall = WAN —Allow/Block—> Peplink/Pepwave Device
For the functionality of the firewall in SSID, it restricts the wireless client who connects to the SSID with port, IP Network, MAC Address, and domain name. For example, if you restrict TCP 8888, any connection with TCP 8888 from the wireless client will be blocked.