Thank you so much for the information! Much appreciated.
Upon following the configuration example above with my RUT240 LAN IP: 10.1.2.1 and VLAN 2 IP: 10.1.3.1, I was able to ping from the VLAN2 subnet to the LAN subnet. Which is not the desired effect of VLAN isolation.
I discovered I need to create a new firewall zone to correspond ONLY to the VLAN, and then under the "network interface" section edit the details, change the Firewall zone to that new zone. My VLAN ID2 name is POS, I created a network interface called POS, and a firewall zone named POS. The Network Interface POS, has its physical settings to POS VLAN, and its firewall zone assigned as POS. Under the firewall zone rules I allowed POS to forward to WAN.
Now, I can ping google.com from VLAN 2 but not clients on the the other subnet (10.1.2.0/24)
One thing; however, is the Teltonika RUT240 responds to ping from its primary LAN IP 10.1.2.1 from the VLAN2 subnet.