You could use LAN_IN rules. They're done in numerical order (1,2,3,..., default)
The router only comes into play when you're crossing subnets.
The router only comes into play when you're crossing subnets.