Yes the IPs are on the VLAN interfaces.
There is no dhcp server for members of vlan2, from what I read so far I can setup PCs with static addresses pointed back to the PC that handles routing for the VLANS. So if it can be done, I would like to be able to give the PCs on vlan2 access to the internet but not allow them to access PCs on vlan1.
So far with the routing of the vlans I’m able to ping a couple addresses on vlan1 from a pc that is on vlan2, but I’m not able to ping any web addresses for example google.com.
The ZS routing table looks something like this:
192.168.20.0/24 ETH00 VLAN 2
Default GW 192.168.194.1