> That was further upthread.
No, that was in all of my replies. I've been consistent about this.
> You could use [VLANs] to make your firewall rules simpler, but then you need routing an multicast forwarding rules.
If you're not going to be running your multicast software on a machine that is wired in to all relevant VLANs (like your edge router), then yeah, if you need cross-VLAN multicast you would need to have multicast forwarding set up on such a machine. You'd need to do the same for broadcast, which is "just" all-nodes multicast.
> In the usual home scenario where there is only 1 networking device, VLANs and subnets both seem to me like their main purpose would be to isolate clients from each other...
Then you're confused about how VLANs and subnetting are typically used.
I can think of three ways to do what I think you're envisioning.
1) Use the "client isolation" feature of WiFi APs. I think this uses something OTHER than VLANs, given that clients get allocated IP addresses from the same subnet as each other.
2) Create a subnet and VLAN per client and program your router to not permit traffic originating from these special subnets to go anywhere other than direct to the router or out to the Internet.
3) Have one or more fairly fancy switches that are programmed to only permit packets to flow from each client port to the router port. (I'm pretty sure that this is conceptually what the often-present WiFi "client isolation" feature is.)
I know that you cannot prevent clients in the same subnet and VLAN from talking to one another unless you have direct intervention by a wireless or wired switch. This is because clients in the same subnet trying to talk to each other don't bother talking to the router and just use ARP (or ND) to find their conversation partners.
I'm not CERTAIN, but I think that if you try to have clients in the same subnet, but on different VLANs, it will work poorly (or not at all) because the router will have a hard time with route selection for incoming traffic, as well as traffic originating on the router to the client subnet.