With the statement that LAN to LAN traffic does not go through the router, but through the switch, you exaggerated a bit ;)
In this case, most of the advanced features of the router software will not work!
iptables -nvL FORWARD
FORWARD string (ACCEPT policy 0 packets, 0 bytes)
pts...