Ok,
Tested the firewall rules on pfSense, can't reach the rightly unreacable vlans (like ceph storage, pve cluster, ...), while can reach the others.
Ssh still getting closed connection after some seconds if I ssh cross-network (cross-vlan).
Ping works seamlessly, seems.