So for example, if you have a host 192.168.0.5 that needs to talk to the gateway 192.168.0.1/24, and your first outbound l3 firewall rule is that 192.168.0.5 is denied to 192.168.0.0/24, traffic will still go through because it's intra-vlan traffic, right?