SSID password on different network server

I have created 2 vlans for IOT , Guest on Netgear wax 610 AP. All works well when i use the Ip address for these. My Lan uses the original router/modem SSID and Password. I am trying to use some devices which are on the IOT vlan which i need to connect to HA on the LAN . If i use the SSID/ Password for IOT i am unable to connect to the device. I assume HA has to be in the IOT subnet also?

Is this correct or is there a rule that i can connect the 2 together?

Apologise in advance as i am just getting to grips with networking and i would appreciate some guidance .

Do you have the proper rules on your interfaces to pass traffic?

At the moment i have these basic rules at the moment 1- Block This firewall & Pass Except to Lan net - allow all. As I said i am extremely new to this. This all i have at the moment to get some ideas. Now i have come against this situation that i am trying solve and understand?