Good point, perhaps the firewall wasn’t restarted?

Anyway I got this to “work”. iptables on the router with the guest wifi didn’t help (at this point it’s a FreshTomato router, not a GL.iNet router, sorry I don’t have info on that), presumably because it’s bridged to my primary router. iptables on my primary router (the 192.168.10.X subnet) did take effect, as noted by how many packets the rule matched in iptables log, and my Google Home Hub being unable to find the LIFX LEDs with the rules enabled.

Unfortunately it was all useless. I blocked both incoming and outgoing packets to my LIFX LEDs and while it successfully disabled their cloud access, it did not disable LAN communication (so the exact opposite of what I wanted).

I can only guess this is because the cellphone app sends UDP packets that aren’t dropped by the router firewall??? I thought those could be routed too, but rejecting everything only blocked cloud access.

Thanks for the help alzhao, I’m going to take this up with LIFX support I guess, even though I’ve had to deal with this for 3+ years, apparently not everyone is so afflicted by incredibly unresponsive lights (across multiple router swaps).