I would like to be able to lockout access to the GUI from certain VLANs. Is there a way to pull that off? Is it a rule on the interfaces?
Just add block rules on the primary lan - the one that normally has access to the admin we'll call it VLAN1. So in VLAN1 rules add a block rule, one for each of the other VLANs that blocks access to the admin and port 80 and 443.