You need 2 rules.
In
name: LONELY_IN
description: guest to LAN/WAN
default action Drop
interface: eth2, direction in
rules:
- allow http. source port 8080, protocol TCP, action Accept
-
- allow ssh. source port 22, protocol TCP, action Accept
- drop guest to LAN. destination: network group LAN_NETWORKS. protocol all, action Drop
Local
name: LONELY_LOCAL
description: guest to router
default action Drop
interface: eth2 direction local
rules:
- allow DNS. destination port 53, protocol TCP/UDP, action Accept
- allow DHCP. destination port 67, protocol UDP, action Accept