So if i want that Network see device and device see Network i need to create two rules?
First Rule: Source 192.168.0.0/24 Destanation 192.168.20.20/32
Second Rule: Source 192.168.20.20/32 Destanation 192.168.0.0/24
And doesn't matter if its traffic between VLANs?
Am I right? It's like standard firewall in Iptables and etc