I resolved it with the rules you have cited, now I use these rules:
VLAN1
VLAN1
- allow all traffic incoming from vlan control [vlan10]
- block all traffic from others vlans [ ! vlan1]
- allow all traffic incoming [to wan and beyond]