Isolated ports are isolated against each other, but not against the non-isolated ports. If it would, you couldn't reach your upstream gateway. You need to implement other security measures like different VLANs terminated and filtered on the firewall or switch ACLs.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.