Multiple VLans for device Separation and Internet-Sharing

Hi folks,

first of all, sorry for my bad english and big excuses, i'm a newbie regarding openwrt.
I've been trying to get this to work - without succes...
What i want:
I have installed OpenWrt 19.07.3 r11063-85e04e9f46 on an RaspberryPi3b
My Vlan setup look like this:

Vlan 3 (eth0.3) is connected to my fully working Guest-Access as a DHCP-Client
Vlan 4 (eth0.4) is established as Static with ip range .4.1/24 and providing DHCP-Service for all Clients connected to vlan4

Vlan3 and vlan4 have their own firewall-zone
My internet connection is on vlan3 - how do i have to configure the device eth0.4 and its firewall rules to get it working, that all clients on eth0.4 do have internet access trough eth0.3 without making all eth0.3 clients avaliable/seeable to the eth0.4 clients

i Hope u can understand me and my problem... :wink:

Allow forwarding from eth0.4 to eth0.3, and add a firewall rule which rejects packets from eth0.4 to the subnet used by eth0.3.

I already gave that a try -> see configuration pics:

IOT = eth0.4
GAST = eth0.3

I do not get internet on IOT devices...